WordPress Vulnerability Report – October 4, 2023

WordPress Vulnerability Report – March 9, 2022

Written by

Dan Knauss
on

October 4, 2023

Last Updated on October 4, 2023

Since last week, 97 total vulnerabilities have emerged in public disclosure. They may affect over two million WordPress sites. There are 50 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 47 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Table of Contents Plus

Plugin Slugtable-of-contents-plus

Installations300,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2309

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2309.

ProfilePress

Product image for Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.

Plugin Slugwp-user-avatar

Installations200,000+

VulnerabilitySensitive Data Exposure

Patched in Version4.13.3

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.13.3.

FooGallery

Product image for Best WordPress Gallery Plugin – FooGallery.

Plugin Slugfoogallery

Installations100,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.3.2

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.3.2.

FooGallery

Product image for Best WordPress Gallery Plugin – FooGallery.

Plugin Slugfoogallery

Installations100,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.3.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.3.2.

iframe

Product image for iframe.

Plugin Slugiframe

Installations100,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version4.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.7.

Advanced Custom Fields: Extended

Product image for Advanced Custom Fields: Extended.

Plugin Slugacf-extended

Installations80,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version0.8.9.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 0.8.9.4.

Astra Bulk Edit

Product image for Astra Bulk Edit.

Plugin Slugastra-bulk-edit

Installations70,000+

VulnerabilityBroken Access Control

Patched in Version1.2.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.8.

Simple Membership

Product image for Simple Membership.

Plugin Slugsimple-membership

Installations50,000+

VulnerabilityPrivilege Escalation

Patched in Version4.3.5

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.3.5.

Simple Membership

Product image for Simple Membership.

Plugin Slugsimple-membership

Installations50,000+

VulnerabilityPrivilege Escalation

Patched in Version4.3.5

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.3.5.

Ditty

Product image for Ditty – Responsive News Tickers, Sliders, and Lists.

Plugin Slugditty-news-ticker

Installations40,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.1.25

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.1.25.

BEAR

Product image for BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.

Plugin Slugwoo-bulk-editor

Installations30,000+

VulnerabilityBroken Access Control

Patched in Version1.1.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.4.

BEAR

Product image for BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.

Plugin Slugwoo-bulk-editor

Installations30,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.1.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.4.

Abandoned Cart Lite for WooCommerce

Product image for Abandoned Cart Lite for WooCommerce.

Plugin Slugwoocommerce-abandoned-cart

Installations30,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version5.16.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.16.0.

WP Job Openings

Product image for WP Job Openings – Job Listing, Career Page and Recruitment Plugin.

Plugin Slugwp-job-openings

Installations30,000+

VulnerabilitySensitive Data Exposure

Patched in Version3.4.3

Severity ScoreLow

The vulnerability has been patched, so you should update to version 3.4.3.

flowpaper

Product image for flowpaper.

Plugin Slugflowpaper-lite-pdf-flipbook

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.0.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.0.4.

Simple Cloudflare Turnstile

Product image for Simple Cloudflare Turnstile – CAPTCHA Alternative.

Plugin Slugsimple-cloudflare-turnstile

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.23.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.23.2.

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce

Product image for WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce.

Plugin Slugwp-event-manager

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.1.38

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.1.38.

Inactive Logout

Product image for Inactive Logout.

Plugin Sluginactive-logout

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version3.2.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.2.3.

Modal Window

Product image for Modal Window – create popup modal window.

Plugin Slugmodal-window

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version5.3.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.3.6.

Options for Twenty Seventeen

Product image for Options for Twenty Seventeen.

Plugin Slugoptions-for-twenty-seventeen

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.5.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.5.1.

bbp style pack

Product image for bbp style pack.

Plugin Slugbbp-style-pack

Installations8,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version5.6.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.6.8.

Brands for WooCommerce

Product image for Brands for WooCommerce.

Plugin Slugbrands-for-woocommerce

Installations6,000+

VulnerabilityBroken Access Control

Patched in Version3.8.2.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.2.3.

WOLF

Product image for WOLF – WordPress Posts Bulk Editor and Manager Professional.

Plugin Slugbulk-editor

Installations5,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.0.7.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.0.7.2.

Active Directory Integration / LDAP Integration

Product image for Active Directory Integration / LDAP Integration.

Plugin Slugldap-login-for-intranet-sites

Installations5,000+

VulnerabilityBroken Access Control

Patched in Version4.2

Severity ScoreLow

The vulnerability has been patched, so you should update to version 4.2.

AI ChatBot

Product image for AI ChatBot.

Plugin Slugchatbot

Installations4,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version4.7.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.7.9.

ActivityPub for WordPress

Product image for ActivityPub.

Plugin Slugactivitypub

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.0.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.0.0.

ActivityPub for WordPress

Product image for ActivityPub.

Plugin Slugactivitypub

Installations3,000+

VulnerabilitySensitive Data Exposure

Patched in Version1.0.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.0.0.

ActivityPub for WordPress

Product image for ActivityPub.

Plugin Slugactivitypub

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.0.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.0.0.

ActivityPub for WordPress

Product image for ActivityPub.

Plugin Slugactivitypub

Installations3,000+

VulnerabilitySensitive Data Exposure

Patched in Version1.0.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.0.0.

Checkfront Online Booking System

Product image for Checkfront Online Booking System.

Plugin Slugcheckfront-wp-booking

Installations3,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.7.

DoLogin Security

Plugin Slugdologin

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.7

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.7.

Import XML and RSS Feeds

Product image for Import XML and RSS Feeds.

Plugin Slugimport-xml-feed

Installations3,000+

VulnerabilityRemote Code Execution (RCE)

Patched in Version2.1.5

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.1.5.

Import XML and RSS Feeds

Product image for Import XML and RSS Feeds.

Plugin Slugimport-xml-feed

Installations3,000+

VulnerabilityArbitrary File Upload

Patched in Version2.1.4

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.1.4.

Track The Click

Product image for Track The Click.

Plugin Slugtrack-the-click

Installations3,000+

VulnerabilitySQL Injection

Patched in Version0.3.12

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 0.3.12.

Anchor Episodes Index (Spotify for Podcasters)

Product image for Anchor Episodes Index (Spotify for Podcasters).

Plugin Sluganchor-episodes-index

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.1.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.1.8.

Comment Blacklist Updater

Product image for Comment Blacklist Updater.

Plugin Slugcomment-blacklist-updater

Installations2,000+

VulnerabilityBroken Access Control

Patched in Version1.2.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.0.

Instant CSS

Product image for Instant CSS.

Plugin Sluginstant-css

Installations2,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.2.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.2.

Pretty Google Calendar

Plugin Slugpretty-google-calendar

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.6.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.0.

OpenHook

Product image for OpenHook.

Plugin Slugthesis-openhook

Installations2,000+

VulnerabilityRemote Code Execution (RCE)

Patched in Version4.3.1

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 4.3.1.

BuddyMeet

Product image for BuddyMeet.

Plugin Slugbuddymeet

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.3.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.3.0.

Pre-Publish Checklist

Product image for Pre-Publish Checklist.

Plugin Slugpre-publish-checklist

Installations1,000+

VulnerabilityBroken Access Control

Patched in Version1.1.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.2.

Simple Posts Ticker

Product image for Simple Posts Ticker – Easy, Lightweight & Flexible.

Plugin Slugsimple-posts-ticker

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.1.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.6.

Simple Posts Ticker

Product image for Simple Posts Ticker – Easy, Lightweight & Flexible.

Plugin Slugsimple-posts-ticker

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.1.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.6.

User Avatar – Reloaded

Product image for User Avatar – Reloaded.

Plugin Sluguser-avatar-reloaded

Installations800+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.2.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.2.

Payment gateway per Product for WooCommerce

Product image for Payment gateway per Product for WooCommerce.

Plugin Slugwoocommerce-product-payments

Installations500+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.2.8

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.2.8.

Staff / Employee Business Directory for Active Directory

Product image for Staff / Employee Business Directory for Active Directory.

Plugin Slugldap-ad-staff-employee-directory-search

Installations10+

VulnerabilityBroken Access Control

Patched in Version1.3

Severity ScoreLow

The vulnerability has been patched, so you should update to version 1.3.

Modern Events Calendar lite

PluginModern Events Calendar Lite

Plugin Slugmodern-events-calendar-lite

VulnerabilityCross Site Scripting (XSS)

Patched in Version7.1.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 7.1.0.

Tiger Forms

Product image for Tiger Forms – Drag and Drop Form Builder.

Plugin Slugtiger-form

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.1.0

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.1.0.

User Activity Log Pro

PluginUser Activity Log Pro

Plugin Sluguser-activity-log-pro

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.3.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.3.4.

User Activity Log Pro

PluginUser Activity Log Pro

Plugin Sluguser-activity-log-pro

VulnerabilityBypass Vulnerability

Patched in Version2.3.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.3.4.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Popup Builder

Product image for Popup Builder – Create highly converting, mobile friendly marketing popups..

Plugin Slugpopup-builder

Installations200,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Unyson

Product image for Unyson.

Plugin Slugunyson

Installations200,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Media Library Assistant

Product image for Media Library Assistant.

Plugin Slugmedia-library-assistant

Installations70,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Timthumb Vulnerability Scanner

Plugin Slugtimthumb-vulnerability-scanner

Installations40,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Mang Board WP

Product image for Mang Board WP.

Plugin Slugmangboard

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Mediavine Control Panel

Plugin Slugmediavine-control-panel

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Schema App Structured Data

Product image for Schema App Structured Data.

Plugin Slugschema-app-structured-data-for-schemaorg

Installations10,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Block Plugin Update

Product image for Block Plugin Update.

Plugin Slugblock-specific-plugin-updates

Installations7,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Simple File List

Plugin Slugsimple-file-list

Installations5,000+

VulnerabilityArbitrary File Deletion

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

WP Job Portal

Product image for WP Job Portal – A Complete Job Board.

Plugin Slugwp-job-portal

Installations3,000+

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched. You should deactivate the plugin.

WP Adminify

Product image for WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders.

Plugin Slugadminify

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Blocks

Product image for Blocks.

Plugin Slugblocks

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Contact Form

Product image for Contact Form.

Plugin Slugcontact-form-ready

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Timely Booking Button

Product image for Timely Booking Button.

Plugin Slugtimely-booking-button

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Tiny Carousel Horizontal Slider

Product image for Tiny Carousel Horizontal Slider.

Plugin Slugtiny-carousel-horizontal-slider

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce ESTO

Plugin Slugwoo-esto

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP Hide Pages

Plugin Slugwp-hide-pages

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Popup contact form

Product image for Popup contact form.

Plugin Slugpopup-contact-form

Installations900+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Popup contact form

Product image for Popup contact form.

Plugin Slugpopup-contact-form

Installations900+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Social Metrics

Plugin Slugsocial-metrics

Installations900+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

The Awesome Feed – Custom Feed

Product image for The Awesome Feed – Custom Feed.

Plugin Slugwp-facebook-feed

Installations900+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Onclick Show Popup

Product image for Onclick show popup.

Plugin Slugonclick-show-popup

Installations400+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Slideshow, Image Slider by 2J

PluginImages Slideshow by 2J

Plugin Slug2j-slideshow

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Add Shortcodes Actions And Filters

PluginAdd Shortcodes Actions And Filters

Plugin Slugadd-actions-and-filters

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contractor Contact Form Website to Workflow Tool

PluginContractor Contact Form Website to Workflow Tool

Plugin Slugcontractor-contact-form-website-to-workflow-tool

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cooked

PluginCooked

Plugin Slugcooked

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CopyRightPro

PluginCopyRightPro

Plugin Slugcopyrightpro

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Comments by Startbit

PluginComments by Startbit

Plugin Slugfacebook-comment-by-vivacity

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome Integration

PluginFont Awesome Integration

Plugin Slugfont-awesome-integration

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome More Icons

PluginFont Awesome More Icons

Plugin Slugfont-awesome-more-icons

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contact form Form For All

PluginContact form Form For All

Plugin Slugformforall

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Keap Landing Pages

PluginKeap Landing Pages

Plugin Sluginfusionsoft-landing-pages

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Backend Localization

PluginBackend Localization

Plugin Slugkau-boys-backend-localization

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Kv TinyMCE Editor Add Fonts

PluginKv TinyMCE Editor Add Fonts

Plugin Slugkv-tinymce-editor-fonts

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Magic Action Box

PluginMagic Action Box

Plugin Slugmagic-action-box

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Remove slug from custom post type

PluginRemove slug from custom post type

Plugin Slugremove-slug-from-custom-post-type

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Responsive header image slider

PluginWP Responsive header image slide

Plugin Slugresponsive-header-image-slider

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Events Rich Snippets for Google

PluginEvents Rich Snippets for Google

Plugin Slugrich-snippets-vevents

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Shockingly Simple Favicon

PluginShockingly Simple Favicon

Plugin Slugshockingly-simple-favicon

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

TM WooCommerce Compare & Wishlist

PluginTM WooCommerce Compare & Wishlist

Plugin Slugtm-woocommerce-compare-wishlist

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Vrm 360 3D Model Viewer

PluginVrm 360 3D Model Viewer

Plugin Slugvrm360

VulnerabilitySensitive Data Exposure

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Captcha

PluginWP Captcha

Plugin Slugwp-captcha

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Captcha

PluginWP Captcha

Plugin Slugwp-captcha

VulnerabilityBypass Vulnerability

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP GPX Maps

PluginWP GPX Map

Plugin Slugwp-gpx-maps

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Jump Menu

PluginWP Jump Menu

Plugin Slugwp-jump-menu

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Site Protector

PluginWP Site Protector

Plugin Slugwp-site-protector

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WWM Social Share On Image Hover

PluginWWM Social Share On Image Hover

Plugin Slugwwm-social-share-on-image-hover

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-10-04 13:30:50.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report – September 27, 2023

WordPress Vulnerability Report: November 2021, Part 3

Written by

Dan Knauss
on

September 27, 2023

Last Updated on September 27, 2023

Since last week, 48 total vulnerabilities have emerged in public disclosure. They may affect over three million WordPress sites. There are 39 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are nine plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Website Builder by SeedProd

Plugin Slugcoming-soon

Installations1,000,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version6.15.15.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 6.15.15.3.

Ad Inserter

Product image for Ad Inserter – Ad Manager & AdSense Ads.

Plugin Slugad-inserter

Installations300,000+

VulnerabilitySensitive Data Exposure

Patched in Version2.7.31

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.7.31.

Ad Inserter

Product image for Ad Inserter – Ad Manager & AdSense Ads.

Plugin Slugad-inserter

Installations300,000+

VulnerabilitySensitive Data Exposure

Patched in Version2.7.31

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.7.31.

Table of Contents Plus

Product image for Table of Contents Plus.

Plugin Slugtable-of-contents-plus

Installations300,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2309

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2309.

WPvivid

Product image for Migration, Backup, Staging – WPvivid.

Plugin Slugwpvivid-backuprestore

Installations300,000+

VulnerabilityArbitrary File Deletion

Patched in Version0.9.90

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 0.9.90.

WPvivid

Product image for Migration, Backup, Staging – WPvivid.

Plugin Slugwpvivid-backuprestore

Installations300,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version0.9.90

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 0.9.90.

iframe

Product image for iframe.

Plugin Slugiframe

Installations100,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version4.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.7.

wpDiscuz

Product image for Comments – wpDiscuz.

Plugin Slugwpdiscuz

Installations80,000+

VulnerabilitySQL Injection

Patched in Version7.6.6

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 7.6.6.

Media Library Assistant

Product image for Media Library Assistant.

Plugin Slugmedia-library-assistant

Installations70,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.11

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.11.

Connect Matomo (WP-Matomo, WP-Piwik)

Product image for Connect Matomo (WP-Matomo, WP-Piwik).

Plugin Slugwp-piwik

Installations60,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.0.29

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.0.29.

Simple Membership

Product image for Simple Membership.

Plugin Slugsimple-membership

Installations50,000+

VulnerabilityPrivilege Escalation

Patched in Version4.3.5

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.3.5.

Simple Membership

Product image for Simple Membership.

Plugin Slugsimple-membership

Installations50,000+

VulnerabilityPrivilege Escalation

Patched in Version4.3.5

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.3.5.

Ditty

Product image for Ditty – Responsive News Tickers, Sliders, and Lists.

Plugin Slugditty-news-ticker

Installations40,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.1.25

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.1.25.

BEAR

Product image for BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.

Plugin Slugwoo-bulk-editor

Installations30,000+

VulnerabilityBroken Access Control

Patched in Version1.1.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.4.

BEAR

Product image for BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.

Plugin Slugwoo-bulk-editor

Installations30,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.1.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.4.

Poptin

Product image for Pop ups, WordPress Exit Intent Popup, Email Pop Up, Lightbox Pop Up, Spin the Wheel, Contact Form Builder – Poptin.

Plugin Slugpoptin

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.3.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.1.

Copy Anything to Clipboard

Product image for Copy Anything to Clipboard.

Plugin Slugcopy-the-code

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.6.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.6.5.

Statify

Product image for Statify – Extended Evaluation.

Plugin Slugextended-evaluation-for-statify

Installations10,000+

VulnerabilityCSV Injection

Patched in Version2.6.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.6.4.

Modal Window

Product image for Modal Window – create popup modal window.

Plugin Slugmodal-window

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version5.3.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.3.6.

Options for Twenty Seventeen

Product image for Options for Twenty Seventeen.

Plugin Slugoptions-for-twenty-seventeen

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.5.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.5.1.

WP Mailto Links

Product image for WP Mailto Links – Protect Email Addresses.

Plugin Slugwp-mailto-links

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.1.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.1.4.

Widget Responsive for Youtube

Product image for Widget Responsive for Youtube.

Plugin Slugyoutube-widget-responsive

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.6.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.2.

iPanorama 360 – WordPress Virtual Tour Builder

Product image for iPanorama 360 –  WordPress Virtual Tour Builder.

Plugin Slugipanorama-360-virtual-tour-builder-lite

Installations7,000+

VulnerabilitySQL Injection

Patched in Version1.8.0

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.8.0.

Drag and Drop Multiple File Upload

Product image for Drag and Drop Multiple File Upload for WooCommerce.

Plugin Slugdrag-and-drop-multiple-file-upload-for-woocommerce

Installations4,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.1.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.1.1.

DoLogin Security

Plugin Slugdologin

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.7

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.7.

Import XML and RSS Feeds

Product image for Import XML and RSS Feeds.

Plugin Slugimport-xml-feed

Installations3,000+

VulnerabilityRemote Code Execution (RCE)

Patched in Version2.1.5

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.1.5.

Import XML and RSS Feeds

Product image for Import XML and RSS Feeds.

Plugin Slugimport-xml-feed

Installations3,000+

VulnerabilityArbitrary File Upload

Patched in Version2.1.4

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.1.4.

Pretty Google Calendar

Plugin Slugpretty-google-calendar

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.6.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.0.

WPSchoolPress

Product image for School Management System – WPSchoolPress.

Plugin Slugwpschoolpress

Installations2,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.2.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.2.5.

Bit Assist

Product image for Chat Button: WhatsApp, Facebook Messenger Chat, Telegram Chat, WeChat, Line Chat, Discord Chat for Customer Support Chat with floating Chat Widget.

Plugin Slugbit-assist

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.

Leaflet Map

Plugin Slugextensions-leaflet-map

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.3.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.3.1.

Simple Posts Ticker

Product image for Simple Posts Ticker – Easy, Lightweight & Flexible.

Plugin Slugsimple-posts-ticker

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.1.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.6.

Simple Posts Ticker

Product image for Simple Posts Ticker – Easy, Lightweight & Flexible.

Plugin Slugsimple-posts-ticker

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.1.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.6.

Funnelforms Free

Product image for Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free.

Plugin Slugfunnelforms-free

Installations800+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.4.

User Avatar – Reloaded

Product image for User Avatar – Reloaded.

Plugin Sluguser-avatar-reloaded

Installations800+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.2.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.2.

Memberlite Shortcodes

Product image for Memberlite Shortcodes.

Plugin Slugmemberlite-shortcodes

Installations700+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.3.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.9.

Serial Codes Generator and Validator with WooCommerce Support

Product image for Serial Codes Generator and Validator with WooCommerce Support.

Plugin Slugserial-codes-generator-and-validator

Installations600+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.4.15

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.4.15.

User Activity Log Pro

PluginUser Activity Log Pro

Plugin Sluguser-activity-log-pro

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.3.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.3.4.

User Activity Log Pro

PluginUser Activity Log Pro

Plugin Sluguser-activity-log-pro

VulnerabilityBypass Vulnerability

Patched in Version2.3.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.3.4.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Popup Builder

Product image for Popup Builder – Create highly converting, mobile friendly marketing popups..

Plugin Slugpopup-builder

Installations200,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Active Directory Integration / LDAP Integration

Product image for Active Directory Integration / LDAP Integration.

Plugin Slugldap-login-for-intranet-sites

Installations5,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreLow

The vulnerability has not been patched. You should deactivate the plugin.

WP Job Portal

Product image for WP Job Portal – A Complete Job Board.

Plugin Slugwp-job-portal

Installations3,000+

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched. You should deactivate the plugin.

Staff / Employee Business Directory for Active Directory

Product image for Staff / Employee Business Directory for Active Directory.

Plugin Slugldap-ad-staff-employee-directory-search

Installations10+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreLow

The vulnerability has not been patched. You should deactivate the plugin.

Easy Registration Forms

PluginEasy Registration Forms

Plugin Slugeasy-registration-forms

VulnerabilitySensitive Data Exposure

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contact Form by FormGet

PluginFormGet Contact Form

Plugin Slugformget-contact-form

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Super Store Finder

PluginSuper Store Finder

Plugin Slugsuperstorefinder-wp

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Vrm 360 3D Model Viewer

PluginVrm 360 3D Model Viewer

Plugin Slugvrm360

VulnerabilitySensitive Data Exposure

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Charts

Pluginwp-charts

Plugin Slugwp-charts

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-09-27 09:32:11.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report – July 19, 2023

WordPress Vulnerability Report – July 19, 2023

Written by

Dan Knauss
on

July 19, 2023

Last Updated on July 19, 2023

Since last week, 80 total vulnerabilities emerged in public disclosure. They may affect over 5 million WordPress sites. There are 55 plugin vulnerabilities with security patches available, so run those updates!

Additionally, there are 23 plugin vulnerabilities and two theme vulnerabilities with no patch available yet. If you discover you are using an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.

Solid Security: The Next Chapter in WordPress Protection

As you know, we’re rebranding publicly, and iThemes is becoming SolidWP. This transition includes new and enhanced features plus a complete interface redesign for our products. In this webinar, our lead developer, Timothy Jacobs, demonstrates the new features coming to Solid Security — formerly known as iThemes Security.

In the video, you’ll get a tour of:

  • the improved dashboard
  • passkeys and the passwordless login experience
  • the all-new firewall
  • virtual patches that protect you when you need them most

Nathan Ingram hosted this sneak preview of the all-new Solid Security. He fielded many terrific questions from the live audience for Timothy and Matt Cromwell, our Senior Director of Customer Experience at StellarWP, so check out that discussion in the last 30 minutes.

News From WordPress

WordPress 6.3 RC1 is ready for download and testing. Because this version is under development, do not install, run, or test this version on production or mission-critical websites. Instead, evaluate RC1 on a test server and site.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

Rank Math SEO

Plugin Slugseo-by-rank-math

Installations2,000,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.0.119.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.0.119.1.

All In One WP Security

Product image for All-In-One Security (AIOS) – Security and Firewall.

Plugin Slugall-in-one-wp-security-and-firewall

Installations1,000,000+

VulnerabilitySensitive Data Exposure of Plaintext Credentials

Patched in Version5.2.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.2.0.

Spectra

Product image for Spectra – WordPress Gutenberg Blocks.

Plugin Slugultimate-addons-for-gutenberg

Installations500,000+

VulnerabilityServer Side Request Forgery (SSRF)

Patched in Version2.6.7

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.6.7.

Spectra

Product image for Spectra – WordPress Gutenberg Blocks.

Plugin Slugultimate-addons-for-gutenberg

Installations500,000+

VulnerabilityBroken Access Control

Patched in Version2.6.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.6.7.

FluentForm

Product image for Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms.

Plugin Slugfluentform

Installations300,000+

VulnerabilitySQL Injection

Patched in Version5.0.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.0.0.

Post SMTP

Product image for POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress.

Plugin Slugpost-smtp

Installations300,000+

VulnerabilityUnauthenticated Stored Cross-Site Scripting via Email

Patched in Version2.5.8

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.5.8.

HT Mega Absolute Addons for Elementor

Product image for HT Mega – Absolute Addons For Elementor.

Plugin Slught-mega-for-elementor

Installations100,000+

VulnerabilityUnauthenticated Privilege Escalation

Patched in Version2.2.1

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.2.1.

ARPP – Yet Another Related Posts Plugin

Product image for YARPP – Yet Another Related Posts Plugin.

Plugin Slugyet-another-related-posts-plugin

Installations100,000+

VulnerabilityAuthenticated (Contributor+) Stored Cross Site Scripting (XSS)

Patched in Version5.30.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.30.4.

kk Star Ratings

Product image for kk Star Ratings.

Plugin Slugkk-star-ratings

Installations90,000+

VulnerabilityRate Manipulation due to IP Spoofing

Patched in Version5.4.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.4.4.

Media Library Assistant

Product image for Media Library Assistant.

Plugin Slugmedia-library-assistant

Installations70,000+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in Version3.0.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.0.8.

Advanced AJAX Product Filters

Product image for Advanced AJAX Product Filters.

Plugin Slugwoocommerce-ajax-filters

Installations60,000+

VulnerabilityBroken Access Control

Patched in Version1.6.3.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.3.4.

HTTP Headers

Product image for HTTP Headers.

Plugin Slughttp-headers

Installations40,000+

VulnerabilityServer Side Request Forgery (SSRF)

Patched in Version1.19.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.19.0.

HTTP Headers

Product image for HTTP Headers.

Plugin Slughttp-headers

Installations40,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.19.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.19.0.

Quiz And Survey Master

Product image for Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress.

Plugin Slugquiz-master-next

Installations40,000+

VulnerabilityBroken Access Control

Patched in Version8.1.11

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 8.1.11.

Super Socializer

Product image for Social Share, Social Login and Social Comments Plugin – Super Socializer.

Plugin Slugsuper-socializer

Installations40,000+

VulnerabilityAuthenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Patched in Version7.13.54

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 7.13.54.

JetFormBuilder

Product image for JetFormBuilder — Dynamic Blocks Form Builder.

Plugin Slugjetformbuilder

Installations30,000+

VulnerabilityAuthenticated Privilege Escalation

Patched in Version3.0.9

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.0.9.

IP2Location Country Blocker

Product image for IP2Location Country Blocker.

Plugin Slugip2location-country-blocker

Installations20,000+

VulnerabilityIP Bypass Vulnerability

Patched in Version2.29.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.29.2.

Yasr – Yet Another Stars Rating

Product image for Yasr – Yet Another Stars Rating.

Plugin Slugyet-another-stars-rating

Installations20,000+

VulnerabilityRace Condition

Patched in Version3.3.9

Severity ScoreLow

The vulnerability has been patched, so you should update to version 3.3.9.

Booking Package SAASPROJECT

Product image for Booking Package.

Plugin Slugbooking-package

Installations10,000+

VulnerabilityUnathenticated Privilege Escalation

Patched in Version1.5.99

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.5.99.

User Activity Log

Product image for User Activity Log.

Plugin Sluguser-activity-log

Installations10,000+

VulnerabilitySQL Injection

Patched in Version1.6.3

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.6.3.

Variation Swatches for WooCommerce

Product image for Variation Swatches for WooCommerce.

Plugin Slugwoo-product-variation-swatches

Installations10,000+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in Version2.3.8

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.3.8.

Zippy

Product image for Zippy.

Plugin Slugzippy

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version1.6.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.3.

Restaurant Menu and Food Ordering by Five Star

Product image for Restaurant Menu and Food Ordering by Five Star Plugins.

Plugin Slugfood-and-drink-menu

Installations8,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.4.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.4.7.

Variation Images Gallery for WooCommerce

Product image for Variation Images Gallery for WooCommerce.

Plugin Slugwoo-product-variation-gallery

Installations8,000+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in Version2.3.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.3.4.

BookingPress

Product image for BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin.

Plugin Slugbookingpress-appointment-booking

Installations7,000+

VulnerabilityUnauth. Server Information Disclosure

Patched in Version1.0.65

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.0.65.

Buy Me a Coffee – Button and Widget Plugin

Product image for Buy Me a Coffee – Button and Widget Plugin.

Plugin Slugbuymeacoffee

Installations6,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.

Buy Me a Coffee – Button and Widget Plugin

Product image for Buy Me a Coffee – Button and Widget Plugin.

Plugin Slugbuymeacoffee

Installations6,000+

VulnerabilityBroken Access Control

Patched in Version3.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.

WooCommerce Product Stock Alert

Product image for WooCommerce Product Stock Alert.

Plugin Slugwoocommerce-product-stock-alert

Installations6,000+

VulnerabilitySensitive Data Exposure

Patched in Version2.0.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.0.2.

WooCommerce Product Stock Alert

Product image for WooCommerce Product Stock Alert.

Plugin Slugwoocommerce-product-stock-alert

Installations6,000+

VulnerabilitySettings Change

Patched in Version2.0.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.0.2.

AnsPress – Question and answer

Product image for AnsPress – Question and answer.

Plugin Sluganspress-question-answer

Installations5,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version4.3.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.3.2.

WPFunnels

Product image for Drag & Drop Sales Funnel Builder for WordPress – WPFunnels.

Plugin Slugwpfunnels

Installations5,000+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in Version2.7.17

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.7.17.

WPFunnels

Product image for Drag & Drop Sales Funnel Builder for WordPress – WPFunnels.

Plugin Slugwpfunnels

Installations5,000+

VulnerabilityInsecure Direct Object References (IDOR)

Patched in Version2.7.16

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.7.16.

Integrate Google Drive

Product image for Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.

Plugin Slugintegrate-google-drive

Installations3,000+

VulnerabilityUnauthenticated Broken Access Control

Patched in Version1.2.0

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 1.2.0.

ARMember

Product image for ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.

Plugin Slugarmember-membership

Installations2,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version4.0.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.0.6.

Authors List

Product image for Authors List.

Plugin Slugauthors-list

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.0.3

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.0.3.

Integration for Contact Form 7 and Salesforce

Product image for Integration for Contact Form 7 and Salesforce.

Plugin Slugcf7-salesforce

Installations2,000+

VulnerabilityOpen Redirection

Patched in Version1.3.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.4.

Gift Cards

Product image for Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported).

Plugin Sluggift-voucher

Installations2,000+

VulnerabilityCross-Site Request Forgery in new_voucher_template.php

Patched in Version4.3.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.3.6.

KB Support – WordPress Help Desk

Product image for KB Support – WordPress Help Desk.

Plugin Slugkb-support

Installations2,000+

VulnerabilityBroken Access Control

Patched in Version1.5.89

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.5.89.

Short URL

Product image for Short URL.

Plugin Slugshorten-url

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.6.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.5.

BuddyBuilder BuddyPress Builder for Elementor

Product image for BuddyPress Builder for Elementor – BuddyBuilder.

Plugin Slugstax-buddy-builder

Installations2,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.7.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.7.4.

Checkout with Zelle on Woocommerce

Product image for Checkout with Zelle on Woocommerce.

Plugin Slugwc-zelle

Installations2,000+

VulnerabilityBroken Access Control

Patched in Version3.1.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.1.1.

Custom Field For WP Job Manager

Product image for Custom Field For WP Job Manager.

Plugin Slugcustom-field-for-wp-job-manager

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.

DirectoryPress

Product image for DirectoryPress – Business Directory And Classified Ad Listing.

Plugin Slugdirectorypress

Installations1,000+

VulnerabilityBroken Access Control

Patched in Version3.6.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.6.3.

Falang multilanguage

Product image for Falang multilanguage for WordPress.

Plugin Slugfalang

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.3.40

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.40.

MF Gig Calendar

Plugin Slugmf-gig-calendar

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.2.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.1.

WP Social AutoConnect

Plugin Slugwp-fb-autoconnect

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version4.6.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.6.2.

MailArchiver

Plugin Slugmailarchiver

Installations100+

VulnerabilityUnauthenticated Stored Cross-Site Scripting via Email Subject

Patched in Version2.11.0

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.11.0.

CartFlows Pro

PluginCartFlows Pro

Plugin Slugcartflows-pro

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in Version1.11.12

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.11.12.

Grid Kit Premium

PluginGrid Kit Premium

Plugin Sluggrid-kit-premium

VulnerabilityMultiple Reflected Cross Site Scripting (XSS)

Patched in Version2.2.0

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.2.0.

Premium Addons PRO

PluginPremium Addons PRO

Plugin Slugpremium-addons-pro

VulnerabilityBroken Access Control

Patched in Version2.9.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.9.1.

Premium Addons PRO

PluginPremium Addons PRO

Plugin Slugpremium-addons-pro

VulnerabilitySensitive Data Exposure

Patched in Version2.9.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.9.1.

WooCommerce GoCardless Gateway

PluginWooCommerce GoCardless Gateway

Plugin Slugwoocommerce-gateway-gocardless

VulnerabilityUnauth. Insecure Direct Object References (IDOR)

Patched in Version2.5.7

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.5.7.

WooCommerce Ship to Multiple Addresses

PluginWooCommerce Ship to Multiple Addresses

Plugin Slugwoocommerce-shipping-multiple-addresses

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in Version3.8.6

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.8.6.

WooCommerce Ship to Multiple Addresses

PluginWooCommerce Ship to Multiple Addresses

Plugin Slugwoocommerce-shipping-multiple-addresses

VulnerabilityBroken Access Control

Patched in Version3.8.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.6.

WooCommerce Warranty Requests

PluginWooCommerce Warranty Requests

Plugin Slugwoocommerce-warranty

VulnerabilityBroken Access Control

Patched in Version2.2.0

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.2.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Chat Button

Product image for Chat Button by GetButton.io.

Plugin Slugwhatshelp-chat-button

Installations50,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Coming Soon Chop Chop

Product image for Coming Soon Chop Chop.

Plugin Slugcc-coming-soon

Installations4,000+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Slider a SlidersPack

Product image for Slider a SlidersPack – Image Slider, Post Slider, ACF Gallery Slider.

Plugin Slugsliderspack-all-in-one-image-sliders

Installations4,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Exit Popups & Onsite Retargeting by OptiMonk

Product image for OptiMonk: Popups, Personalization & A/B Testing.

Plugin Slugexit-intent-popups-by-optimonk

Installations3,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Social Media Icons Widget

Plugin Slugspoontalk-social-media-icons-widget

Installations3,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Easyship WooCommerce Shipping Rates

Product image for Easyship WooCommerce Shipping Rates.

Plugin Slugeasyship-woocommerce-shipping-rates

Installations2,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WPSchoolPress

Product image for School Management System – WPSchoolPress.

Plugin Slugwpschoolpress

Installations2,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WPAdmin AWS CDN

Product image for WPAdmin AWS CDN.

Plugin Slugaws-cdn-by-wpadmin

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Contact Form Generator

Product image for Contact Form Generator : Creative form builder for WordPress.

Plugin Slugcontact-form-generator

Installations1,000+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Contact Form to Any API

Product image for Contact Form to Any API.

Plugin Slugcontact-form-to-any-api

Installations1,000+

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Shortcode IMDB

Product image for Shortcode IMDB.

Plugin Slugshortcode-imdb

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Radio Forge Muses Player with Skins

Product image for Radio Forge Muses Player with Skins.

Plugin Slugradio-forge

Installations900+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Replace Word

Product image for Replace Word.

Plugin Slugreplace-word

Installations900+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Art Direction

Plugin Slugart-direction

Installations800+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WPBulky

Product image for WPBulky – WordPress Bulk Edit Post Types.

Plugin Slugwpbulky-wp-bulk-edit-post-types

Installations200+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

ShopConstruct

Product image for ShopConstruct – Product Catalog, Shopping Cart and eCommerce solution for Store.

Plugin Slugshopconstruct

Installations60+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Dovetail

Plugin Slugdovetail

Installations10+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

YourMembership Single Sign On

Plugin Sluglogin-with-yourmembership

Installations10+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

YourMembership Single Sign On

Plugin Sluglogin-with-yourmembership

Installations10+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Twittee Text Tweet

Product image for Twittee Text Tweet.

Plugin Slugtwittee-text-tweet

Installations10+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Mail Control

PluginMail Control

Plugin Slugmail-control

VulnerabilityUnauthenticated Stored Cross Site Scripting (XSS) via Email Subject

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

PDQ CSV

Product image for PDQ CSV.

Plugin Slugpdq-csv

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP Default Feature Image

Product image for WP Default Feature Image.

Plugin Slugwp-default-feature-image

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.

RealHomes

ThemeRealHomes

Theme Slugrealhomes

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should switch themes.

RealHomes

ThemeRealHomes

Theme Slugrealhomes

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should switch themes.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-07-19 12:06:52.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report – September 20, 2023

WordPress vulnerability report

Written by

Dan Knauss
on

September 20, 2023

Last Updated on September 20, 2023

Since last week, 57 total vulnerabilities emerged in public disclosure. They may affect over five million WordPress sites. There are 37 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 20 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Website Builder by SeedProd

Plugin Slugcoming-soon

Installations1,000,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version6.15.15.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 6.15.15.3.

Essential Addons for Elementor

Product image for Essential Addons for Elementor.

Plugin Slugessential-addons-for-elementor-lite

Installations1,000,000+

VulnerabilityPrivilege Escalation

Patched in Version5.8.9

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 5.8.9.

Enable Media Replace

Product image for Enable Media Replace.

Plugin Slugenable-media-replace

Installations600,000+

VulnerabilityPHP Object Injection

Patched in Version4.1.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.1.3.

Fluent Forms

Product image for Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms.

Plugin Slugfluentform

Installations300,000+

VulnerabilityBroken Access Control

Patched in Version5.0.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.0.9.

ShortPixel Image Optimizer

Product image for ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF.

Plugin Slugshortpixel-image-optimiser

Installations300,000+

VulnerabilityPHP Object Injection

Patched in Version5.4.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.4.2.

WPvivid

Product image for Migration, Backup, Staging – WPvivid.

Plugin Slugwpvivid-backuprestore

Installations300,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version0.9.91

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 0.9.91.

WPvivid Backup Plugin

Product image for Migration, Backup, Staging – WPvivid.

Plugin Slugwpvivid-backuprestore

Installations300,000+

VulnerabilityPrivilege Escalation

Patched in Version0.9.91

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 0.9.91.

PageLayer

Product image for Page Builder: Pagelayer – Drag and Drop website builder.

Plugin Slugpagelayer

Installations200,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.7.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.7.7.

ProfilePress

Product image for Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.

Plugin Slugwp-user-avatar

Installations200,000+

VulnerabilityPrivilege Escalation

Patched in Version4.13.2

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.13.2.

ProfilePress

Product image for Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.

Plugin Slugwp-user-avatar

Installations200,000+

VulnerabilityBroken Access Control

Patched in Version4.13.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.13.2.

Essential Blocks

Product image for Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates.

Plugin Slugessential-blocks

Installations100,000+

VulnerabilityPHP Object Injection

Patched in Version4.2.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.2.1.

Modula

Product image for Customizable WordPress Gallery Plugin – Modula Image Gallery.

Plugin Slugmodula-best-grid-gallery

Installations100,000+

VulnerabilityBroken Access Control

Patched in Version2.7.5

Severity ScoreLow

The vulnerability has been patched, so you should update to version 2.7.5.

Slimstat Analytics

Product image for Slimstat Analytics.

Plugin Slugwp-slimstat

Installations100,000+

VulnerabilitySQL Injection

Patched in Version5.0.10

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 5.0.10.

wpDiscuz

Product image for Comments – wpDiscuz.

Plugin Slugwpdiscuz

Installations80,000+

VulnerabilitySQL Injection

Patched in Version7.6.6

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 7.6.6.

wpDiscuz

Product image for Comments – wpDiscuz.

Plugin Slugwpdiscuz

Installations80,000+

VulnerabilityInsecure Direct Object References (IDOR)

Patched in Version7.6.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 7.6.4.

wpDiscuz

Product image for Comments – wpDiscuz.

Plugin Slugwpdiscuz

Installations80,000+

VulnerabilityInsecure Direct Object References (IDOR)

Patched in Version7.6.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 7.6.4.

Booster for WooCommerce

Product image for Booster for WooCommerce.

Plugin Slugwoocommerce-jetpack

Installations60,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version7.1.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 7.1.1.

Booster for WooCommerce

Product image for Booster for WooCommerce.

Plugin Slugwoocommerce-jetpack

Installations60,000+

VulnerabilitySensitive Data Exposure

Patched in Version7.1.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 7.1.1.

Feeds for YouTube

Product image for Feeds for YouTube (YouTube video, channel, and gallery plugin).

Plugin Slugfeeds-for-youtube

Installations50,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.1.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.1.2.

File Manager Pro

Product image for File Manager Pro – Filester.

Plugin Slugfilester

Installations50,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.8

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.8.

MapPress Maps for WordPress

Product image for MapPress Maps for WordPress.

Plugin Slugmappress-google-maps-for-wordpress

Installations50,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.88.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.88.5.

PowerPress

Product image for PowerPress Podcasting plugin by Blubrry.

Plugin Slugpowerpress

Installations40,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version11.0.11

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 11.0.11.

WP Customer Reviews

Product image for WP Customer Reviews.

Plugin Slugwp-customer-reviews

Installations30,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.6.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.6.7.

Poptin

Product image for Pop ups, WordPress Exit Intent Popup, Email Pop Up, Lightbox Pop Up, Spin the Wheel, Contact Form Builder – Poptin.

Plugin Slugpoptin

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.3.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.1.

Welcart e-Commerce

Product image for Welcart e-Commerce.

Plugin Slugusc-e-shop

Installations20,000+

VulnerabilitySQL Injection

Patched in Version2.8.22

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.8.22.

WordPress File Upload

Product image for WordPress File Upload.

Plugin Slugwp-file-upload

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version4.23.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.23.3.

Statify

Product image for Statify – Extended Evaluation.

Plugin Slugextended-evaluation-for-statify

Installations10,000+

VulnerabilityCSV Injection

Patched in Version2.6.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.6.4.

MasterStudy LMS

Product image for MasterStudy LMS WordPress Plugin – for Online Courses and Education.

Plugin Slugmasterstudy-lms-learning-management-system

Installations10,000+

VulnerabilityPrivilege Escalation

Patched in Version3.0.18

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.0.18.

Herd Effects

Product image for Herd Effects – fake notifications and social proof plugin.

Plugin Slugmwp-herd-effect

Installations5,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version5.2.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.2.3.

WPSchoolPress

Product image for School Management System – WPSchoolPress.

Plugin Slugwpschoolpress

Installations2,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.2.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.2.5.

Bit Assist

Product image for Chat Button: WhatsApp, Facebook Messenger Chat, Telegram Chat, WeChat, Line Chat, Discord Chat for Customer Support Chat with floating Chat Widget.

Plugin Slugbit-assist

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.

Funnelforms Free

Product image for Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free.

Plugin Slugfunnelforms-free

Installations800+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.4.

Testimonial Slider Shortcode

Product image for Testimonial Slider Shortcode.

Plugin Slugtestimonial-slider-shortcode

Installations400+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.1.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.9.

Essential Blocks Pro

PluginEssential Blocks Pro

Plugin Slugessential-blocks-pro

VulnerabilityPHP Object Injection

Patched in Version1.1.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.1.1.

Checkout Field Editor

PluginCheckout Field Editor

Plugin Slugwoocommerce-checkout-field-editor

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.7.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.7.5.

WooCommerce CVR Payment Gateway

PluginWooCommerce CVR Payment Gateway

Plugin Slugwoocommerce-cvr-payment-gateway

VulnerabilityBroken Access Control

Patched in Version6.1.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 6.1.0.

WooCommerce EAN Payment Gateway

PluginWooCommerce EAN Payment Gateway

Plugin Slugwoocommerce-ean-payment-gateway

VulnerabilityBroken Access Control

Patched in Version6.1.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 6.1.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Quiz And Survey Master

Product image for Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress.

Plugin Slugquiz-master-next

Installations40,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Read More & Accordion

Product image for Read More & Accordion.

Plugin Slugexpand-maker

Installations20,000+

VulnerabilityPHP Object Injection

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Allow PHP in Posts and Pages

PluginAllow PHP in Posts and Pages

Plugin Slugallow-php-in-posts-and-pages

VulnerabilityRemote Code Execution (RCE)

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Awesome Weather Widget

PluginAwesome Weather Widget

Plugin Slugawesome-weather

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

BAN Users

PluginBAN Users

Plugin Slugban-users

VulnerabilityPrivilege Escalation

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Crayon Syntax Highlighter

PluginCrayon Syntax Highlighter

Plugin Slugcrayon-syntax-highlighter

VulnerabilityServer Side Request Forgery (SSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Dropbox Folder Share

PluginDropbox Folder Share

Plugin Slugdropbox-folder-share

VulnerabilityServer Side Request Forgery (SSRF)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Dropbox Folder Share

PluginDropbox Folder Share

Plugin Slugdropbox-folder-share

VulnerabilityLocal File Inclusion

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Horizontal scrolling announcement

PluginHorizontal scrolling announcement

Plugin Slughorizontal-scrolling-announcement

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Horizontal scrolling announcement

PluginHorizontal scrolling announcement

Plugin Slughorizontal-scrolling-announcement

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Google Maps Plugin by Intergeo

PluginGoogle Maps Plugin by Intergeo

Plugin Slugintergeo-maps

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

JQuery Accordion Menu Widget

PluginJQuery Accordion Menu Widget

Plugin Slugjquery-vertical-accordion-menu

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Leyka

PluginLeyka

Plugin Slugleyka

VulnerabilitySensitive Data Exposure

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Login with phone number

PluginLogin with phone number

Plugin Sluglogin-with-phone-number

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Photospace Responsive

PluginPhotospace Responsive

Plugin Slugphotospace-responsive

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simplr Registration Form Plus+

PluginSimplr Registration Form Plus+

Plugin Slugsimplr-registration-form

VulnerabilityInsecure Direct Object References (IDOR)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Super Store Finder

PluginSuper Store Finder

Plugin Slugsuperstorefinder-wp

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Beta Tester

PluginWooCommerce Beta Tester

Plugin Slugwoocommerce-beta-tester

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP User Control

PluginWP User Control

Plugin Slugwp-user-control

VulnerabilityOther Vulnerability Type

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WS Facebook Like Box Widget

PluginWS Facebook Like Box Widget

Plugin Slugws-facebook-likebox

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-09-20 12:50:19.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report – September 6, 2023

WordPress Vulnerability Report

Written by

Dan Knauss
on

September 6, 2023

Last Updated on September 6, 2023

Since last week, 95 total vulnerabilities emerged in public disclosure. They may affect over two million WordPress sites. There are 32 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 60 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

FREE ONLINE TRAINING EVENT SEPT 6TH @ 1:00 P.M. (CT)

Discover essential best practices for safeguarding your WordPress website through proactive security measures. Join WordPress security expert Thomas Raef as he explains the art and science of WordPress security, focusing on three key dimensions: hosting, WordPress configurations, and user management. You’ll also learn how Solid Security equips users with tools that diminish hacking risks, focusing on safeguarding plugins, themes, and user accounts.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

GTranslate

Product image for Translate WordPress with GTranslate.

Plugin Sluggtranslate

Installations500,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.0.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.0.4.

Forminator

Product image for Forminator – Contact Form, Payment Form & Custom Form Builder.

Plugin Slugforminator

Installations400,000+

VulnerabilityArbitrary File Upload

Patched in Version1.25.0

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 1.25.0.

Metform Elementor Contact Form Builder

Product image for Metform Elementor Contact Form Builder.

Plugin Slugmetform

Installations200,000+

VulnerabilitySensitive Data Exposure

Patched in Version3.3.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.3.2.

Social Media & Share Icons

Product image for Social Media Share Buttons & Social Sharing Icons.

Plugin Slugultimate-social-media-icons

Installations200,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.8.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.8.4.

GiveWP

Product image for GiveWP – Donation Plugin and Fundraising Platform.

Plugin Sluggive

Installations100,000+

VulnerabilityPrivilege Escalation

Patched in Version2.33.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.33.1.

UserFeedback Lite

Product image for User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds.

Plugin Sluguserfeedback-lite

Installations100,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.0.8

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.0.8.

Slimstat Analytics

Product image for Slimstat Analytics.

Plugin Slugwp-slimstat

Installations100,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version5.0.10

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.0.10.

Email Encoder

Product image for Email Encoder – Protect Email Addresses and Phone Numbers.

Plugin Slugemail-encoder-bundle

Installations80,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.1.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.1.8.

Folders

Product image for Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager.

Plugin Slugfolders

Installations60,000+

VulnerabilityArbitrary File Upload

Patched in Version2.9.3

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.9.3.

Popup Box

Product image for Popup box.

Plugin Slugays-popup-box

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.7.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.7.2.

GS Logo Slider

Product image for Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation.

Plugin Sluggs-logo-slider

Installations20,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.4.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.4.3.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.

Plugin Slugwedevs-project-manager

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.6.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.6.1.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.

Plugin Slugwedevs-project-manager

Installations10,000+

VulnerabilitySQL Injection

Patched in Version2.6.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.6.1.

WP Super Minify

Product image for WP Super Minify.

Plugin Slugwp-super-minify

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.

Post to Google My Business (Google Business Profile)

Product image for Post to Google My Business (Google Business Profile).

Plugin Slugpost-to-google-my-business

Installations9,000+

VulnerabilityBroken Access Control

Patched in Version3.1.15

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.1.15.

SureCart

Product image for WordPress Ecommerce For Creating Fast Online Stores – By SureCart.

Plugin Slugsurecart

Installations8,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.5.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.5.1.

HollerBox

Product image for Fast & Effective Popups & Lead-Generation for WordPress – HollerBox.

Plugin Slugholler-box

Installations5,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.3.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.3.3.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.

Plugin Slugorder-tracking

Installations4,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.3.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.3.7.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.

Plugin Slugorder-tracking

Installations4,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.3.7

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.3.7.

Leyka

Product image for Leyka.

Plugin Slugleyka

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.30.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.30.3.

WP Search Analytics

Product image for WP Search Analytics.

Plugin Slugsearch-analytics

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.4.8

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.4.8.

Sitekit

Product image for Sitekit.

Plugin Slugsitekit

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.4.

Prevent files / folders access

Product image for Prevent files / folders access.

Plugin Slugprevent-file-access

Installations1,000+

VulnerabilityArbitrary File Upload

Patched in Version2.5.2

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.5.2.

WP Pipes

Product image for WP Pipes.

Plugin Slugwp-pipes

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.4.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.4.1.

Photo Gallery Slideshow & Masonry Tiled Gallery

Product image for Photo Gallery Slideshow & Masonry Tiled Gallery.

Plugin Slugwp-responsive-photo-gallery

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.0.14

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.0.14.

RSVPMaker

Product image for RSVPMaker.

Plugin Slugrsvpmaker

Installations400+

VulnerabilitySQL Injection

Patched in Version10.6.7

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 10.6.7.

AffiliateWP

PluginAffiliateWP

Plugin Slugaffiliatewp

VulnerabilityBroken Access Control

Patched in Version2.14.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.14.1.

All-in-One WP Migration Box Extension

PluginAll-in-One WP Migration Box Extension

Plugin Slugall-in-one-wp-migration-box-extension

VulnerabilityBroken Access Control

Patched in Version1.54

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.54.

All-in-One WP Migration Dropbox Extension

PluginAll-in-One WP Migration Dropbox Extension

Plugin Slugall-in-one-wp-migration-dropbox-extension

VulnerabilityBroken Access Control

Patched in Version3.76

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.76.

All-in-One WP Migration Google Drive Extension

PluginAll-in-One WP Migration Google Drive Extension

Plugin Slugall-in-one-wp-migration-gdrive-extension

VulnerabilityBroken Access Control

Patched in Version2.80

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.80.

All-in-One WP Migration OneDrive Extension

PluginAll-in-One WP Migration OneDrive Extension

Plugin Slugall-in-one-wp-migration-onedrive-extension

VulnerabilityBroken Access Control

Patched in Version1.67

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.67.

Happy Elementor Addons Pro

PluginHappy Elementor Addons Pro

Plugin Slughappy-elementor-addons-pro

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.8.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.8.1.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

PowerPress Podcasting plugin by Blubrry

Product image for PowerPress Podcasting plugin by Blubrry.

Plugin Slugpowerpress

Installations40,000+

VulnerabilityServer Side Request Forgery (SSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Conversion Tracking

Product image for WooCommerce Conversion Tracking.

Plugin Slugwoocommerce-conversion-tracking

Installations40,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Addons for Contact Form 7

Product image for Ultimate Addons for Contact Form 7.

Plugin Slugultimate-addons-for-contact-form-7

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Directorist

Product image for Directorist – WordPress Business Directory Plugin with Classified Ads Listings.

Plugin Slugdirectorist

Installations10,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Export Import Menus

Product image for Export Import Menus.

Plugin Slugexport-import-menus

Installations10,000+

VulnerabilityArbitrary File Upload

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched. You should deactivate the plugin.

Legal Pages

Product image for Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator.

Plugin Sluglegal-pages

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener by MyThemeShop

Product image for URL Shortener by MyThemeShop.

Plugin Slugmts-url-shortener

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Texty

Product image for Texty – SMS Notification for WordPress, WooCommerce, Dokan and more.

Plugin Slugtexty

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

weMail

Product image for weMail – Email Marketing, Newsletter, Optin Forms, Subscribers WordPress Plugin.

Plugin Slugwemail

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Better Elementor Addons

Product image for Better Elementor Addons.

Plugin Slugbetter-elementor-addons

Installations7,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Easy Coming Soon

Product image for Easy Coming Soon.

Plugin Slugeasy-coming-soon

Installations7,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Login and Logout Redirect

Product image for Login and Logout Redirect.

Plugin Sluglogin-and-logout-redirect

Installations7,000+

VulnerabilityOpen Redirection

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

authLdap

Plugin Slugauthldap

Installations6,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

authLdap

Plugin Slugauthldap

Installations6,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

LuckyWP Scripts Control

Product image for LuckyWP Scripts Control.

Plugin Slugluckywp-scripts-control

Installations6,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Multi-column Tag Map

Product image for Multi-column Tag Map.

Plugin Slugmulti-column-tag-map

Installations6,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Responsive Gallery Grid

Product image for Responsive Gallery Grid.

Plugin Slugresponsive-gallery-grid

Installations6,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Social Share Boost

Plugin Slugsocial-share-boost

Installations6,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Unlimited Elementor Inner Sections By BoomDevs

Product image for Unlimited Elementor Inner Sections By BoomDevs.

Plugin Slugunlimited-elementor-inner-sections-by-boomdevs

Installations6,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

weDocs – Knowledgebase and Documentation Plugin for WordPress

Product image for weDocs – Knowledgebase and Documentation Plugin for WordPress.

Plugin Slugwedocs

Installations6,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

MakeStories (for Google Web Stories)

Product image for MakeStories (for Google Web Stories).

Plugin Slugmakestories-helper

Installations5,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

MyCryptoCheckout

Product image for MyCryptoCheckout – Bitcoin, Ethereum, and 100+ altcoins for WooCommerce.

Plugin Slugmycryptocheckout

Installations5,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Remove/hide Author, Date, Category Like Entry-Meta

Product image for Remove/hide Author, Date, Category Like Entry-Meta.

Plugin Slugremovehide-author-date-category-like-entry-meta

Installations5,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Surfer

Product image for Surfer – WordPress Plugin.

Plugin Slugsurferseo

Installations5,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Leadster

Product image for Leadster.

Plugin Slugleadster-marketing-conversacional

Installations4,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Ovic Product Bundle

Product image for Ovic Product Bundle.

Plugin Slugovic-product-bundle

Installations4,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Pricing Deals for WooCommercePricing Deals for WooCommerce

Plugin Slugpricing-deals-for-woocommerce

Installations4,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP users media

Plugin Slugwp-users-media

Installations4,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Migration Plugin DB & Files – WP Synchro

Product image for WP Synchro – WordPress Migration Plugin for Database & Files.

Plugin Slugwpsynchro

Installations4,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Live News

Product image for Live News.

Plugin Sluglive-news-lite

Installations3,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Realbig

Plugin Slugrealbig-media

Installations3,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

TelSender

Product image for TelSender – ?ontact form 7, Events, Wpforms  and wooccommerce to telegram bot.

Plugin Slugtelsender

Installations3,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce PensoPay

Plugin Slugwoo-pensopay

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Hide admin notices – Admin Notification Center

Plugin Slugwp-admin-notification-center

Installations2,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WRC Pricing Tables

Product image for WRC Pricing Tables – WordPress Responsive CSS3 Pricing Tables.

Plugin Slugwrc-pricing-tables

Installations2,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Bulk NoIndex & NoFollow Toolkit

Plugin Slugbulk-noindex-nofollow-toolkit-by-mad-fish

Installations1,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Exclusive Team for Elementor

Product image for Exclusive Team for Elementor.

Plugin Slugexclusive-team-for-elementor

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Goods Catalog

Plugin Sluggoods-catalog

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Olive One Click Demo Import

Product image for Olive One Click Demo Import.

Plugin Slugolive-one-click-demo-import

Installations1,000+

VulnerabilityArbitrary File Upload

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched. You should deactivate the plugin.

Stock Quotes List

Product image for Stock Quotes List.

Plugin Slugstock-quotes-list

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Product Category Showcase for WooCommerce

Product image for Product Category Showcase for WooCommerce.

Plugin Slugwc-category-showcase

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WiserNotify Social Proof

Product image for WiserNotify Social Proof & FOMO Notification, WooCommerce Sales Popup, Review Popups, Notification Bars & Urgency Widgets.

Plugin Slugwiser-notify

Installations1,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP Bannerize Pro

Product image for WP Bannerize Pro.

Plugin Slugwp-bannerize-pro

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Tilda Publishing

Plugin Slugtilda-publishing

Installations900+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Easy Newsletter Signups

Product image for Easy Newsletter Signups.

Plugin Slugeasy-newsletter-signups

Installations800+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Snap Pixel

Product image for Snap Pixel.

Plugin Slugsnap-pixel

Installations800+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Product image for Woocommerce Support System.

Plugin Slugwc-support-system

Installations300+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Woocommerce Support System

Product image for Woocommerce Support System.

Plugin Slugwc-support-system

Installations300+

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Localize Remote Images

Plugin Sluglocalize-remote-images

Installations10+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Bridge Core

PluginBridge Core

Plugin Slugbridge-core

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

WordPress CTA

PluginWordPress CTA

Plugin Slugeasy-sticky-sidebar

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Font Awesome 4 Menus

PluginFont Awesome 4 Menus

Plugin Slugfont-awesome-4-menus

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

GuruWalk Affiliates

Plugin Slugguruwalk-affiliates

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Maintenance Switch

PluginMaintenance Switch

Plugin Slugmaintenance-switch

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sermon’e – Sermons Online

PluginSermon’e – Sermons Online

Plugin Slugsermone-online-sermons-management

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

SIS Handball

PluginSIS Handball

Plugin Slugsis-handball

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Smarty for WordPress

PluginSmarty for WordPress

Plugin Slugsmarty-for-wordpress

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Use Memcached

PluginUse Memcached

Plugin Sluguse-memcached

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-dTree

PluginWP-dTree

Plugin Slugwp-dtree-30

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP-dTree

PluginWP-dTree

Plugin Slugwp-dtree-30

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Attorney

Product image for Attorney.

Theme Slugattorney

Downloads51,489

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Arya Multipurpose Pro

ThemeArya Multipurpose Pro

Theme Slugarya-multipurpose-pro

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Everest News Pro

ThemeEverest News Pro

Theme Slugeverest-news-pro

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-09-06 09:21:10.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report – August 30, 2023

WordPress Vulnerability Report – July 19, 2023

Written by

Dan Knauss
on

August 30, 2023

Last Updated on August 30, 2023

Since last week, 56 total vulnerabilities emerged in public disclosure. They may affect over two million WordPress sites. There are 28 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 28 plugin vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

ElementsKit Lite

Plugin Slugelementskit-lite

Installations1,000,000+

VulnerabilityBroken Access Control

Patched in Version2.9.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.9.1.

Hide My WP Ghost – Security Plugin

Product image for Hide My WP Ghost – Security Plugin.

Plugin Slughide-my-wp

Installations200,000+

VulnerabilityBypass Vulnerability

Patched in Version5.0.26

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.0.26.

Slimstat Analytics

Product image for Slimstat Analytics.

Plugin Slugwp-slimstat

Installations100,000+

VulnerabilityBroken Access Control

Patched in Version5.0.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.0.6.

Slimstat Analytics

Product image for Slimstat Analytics.

Plugin Slugwp-slimstat

Installations100,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version5.0.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.0.9.

Folders

Product image for Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager.

Plugin Slugfolders

Installations60,000+

VulnerabilityArbitrary File Upload

Patched in Version2.9.3

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.9.3.

iThemes Sync

Product image for iThemes Sync.

Plugin Slugithemes-sync

Installations50,000+

VulnerabilityBroken Access Control

Patched in Version2.1.14

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.1.14.

FV Flowplayer Video Player

Product image for FV Flowplayer Video Player.

Plugin Slugfv-wordpress-flowplayer

Installations30,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version7.5.39.7212

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 7.5.39.7212.

Donation Forms by Charitable

Product image for Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress.

Plugin Slugcharitable

Installations10,000+

VulnerabilityPrivilege Escalation

Patched in Version1.7.0.13

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 1.7.0.13.

ReviewX

Product image for ReviewX – Multi-criteria Rating & Reviews for WooCommerce.

Plugin Slugreviewx

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version1.6.18

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.18.

URL Shortify

Product image for URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPress.

Plugin Slugurl-shortify

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.7.6

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.7.6.

Min Max Control

Product image for Min Max Control – Min Max Quantity & Step Control for WooCommerce.

Plugin Slugwoo-min-max-quantity-step-control-single

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version4.6

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.6.

Category Slider for WooCommerce

Product image for Category Slider for WooCommerce.

Plugin Slugwoo-category-slider-grid

Installations9,000+

VulnerabilityBroken Access Control

Patched in Version1.4.16

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.4.16.

Herd Effects

Product image for Herd Effects – fake notifications and social proof plugin.

Plugin Slugmwp-herd-effect

Installations5,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version5.2.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.2.4.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.

Plugin Slugorder-tracking

Installations4,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.3.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.3.7.

Order Tracking Pro

Product image for Order Tracking – WordPress Status Tracking Plugin.

Plugin Slugorder-tracking

Installations4,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.3.7

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.3.7.

DoLogin Security

Plugin Slugdologin

Installations3,000+

VulnerabilityBypass Vulnerability

Patched in Version3.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.7.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slugwoo-pdf-invoice-builder

Installations3,000+

VulnerabilityBroken Access Control

Patched in Version1.2.92

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.92.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slugwoo-pdf-invoice-builder

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.2.91

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.91.

WP Adminify

Product image for WP Adminify – WordPress Dashboard Customization | Custom Login | Admin Columns | Dashboard Widget | Media Library Folders.

Plugin Slugadminify

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.1.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.1.6.

Premmerce User Roles

Product image for Premmerce User Roles.

Plugin Slugpremmerce-user-roles

Installations1,000+

VulnerabilityBroken Access Control

Patched in Version1.0.13

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.0.13.

Save as PDF plugin by Pdfcrowd

Plugin Slugsave-as-pdf-by-pdfcrowd

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.16.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.16.1.

Event Tickets with Ticket Scanner

Product image for Event Tickets with Ticket Scanner.

Plugin Slugevent-tickets-with-ticket-scanner

Installations600+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.5.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.5.5.

Push Notification for Post and BuddyPress

Plugin Slugpush-notification-for-post-and-buddypress

Installations200+

VulnerabilityBroken Access Control

Patched in Version1.64

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.64.

WP VK-??????

Product image for WP VK-???????????/??/?????????.

Plugin Slugwp-vk

Installations100+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.3.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.4.

Save as Image plugin by Pdfcrowd

Plugin Slugsave-as-image-by-pdfcrowd

Installations30+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.16.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.16.1.

Appointment booking addon for Gravity Forms

PlugingAppointments

Plugin SluggAppointments

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.10.0

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.10.0.

Jupiter X Core

PluginJupiterX Core

Plugin Slugjupiterx-core

VulnerabilityArbitrary File Upload

Patched in Version3.3.8

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 3.3.8.

Jupiter X Core

PluginJupiterX Core

Plugin Slugjupiterx-core

VulnerabilityPrivilege Escalation

Patched in Version3.4.3

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 3.4.3.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Royal Elementor Addons

Product image for Royal Elementor Addons and Templates.

Plugin Slugroyal-elementor-addons

Installations200,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Post and Page Builder by BoldGrid

Product image for Post and Page Builder by BoldGrid – Visual Drag and Drop Editor.

Plugin Slugpost-and-page-builder

Installations100,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Collapse-O-Matic

Product image for Collapse-O-Matic.

Plugin Slugjquery-collapse-o-matic

Installations60,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Master Elementor Addons

Product image for Master Addons for Elementor.

Plugin Slugmaster-addons

Installations40,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Ultimate Addons for Contact Form 7

Product image for Ultimate Addons for Contact Form 7.

Plugin Slugultimate-addons-for-contact-form-7

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

URL Shortener by MyThemeShop

Product image for URL Shortener by MyThemeShop.

Plugin Slugmts-url-shortener

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Landing Page Builder

Product image for Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages.

Plugin Slugpage-builder-add

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP Super Minify

Product image for WP Super Minify.

Plugin Slugwp-super-minify

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Easy Coming Soon

Product image for Easy Coming Soon.

Plugin Slugeasy-coming-soon

Installations7,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

LuckyWP Scripts Control

Product image for LuckyWP Scripts Control.

Plugin Slugluckywp-scripts-control

Installations6,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Social Share Boost

Plugin Slugsocial-share-boost

Installations6,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

MakeStories (for Google Web Stories)

Product image for MakeStories (for Google Web Stories).

Plugin Slugmakestories-helper

Installations5,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.

Plugin Slugsimple-urls

Installations5,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.

Plugin Slugsimple-urls

Installations5,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.

Plugin Slugsimple-urls

Installations5,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Vertical Marquee Plugin

Product image for Vertical marquee plugin.

Plugin Slugvertical-marquee-plugin

Installations4,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP users media

Plugin Slugwp-users-media

Installations4,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP Search Analytics

Product image for WP Search Analytics.

Plugin Slugsearch-analytics

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Sitekit

Product image for Sitekit.

Plugin Slugsitekit

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Olive One Click Demo Import

Product image for Olive One Click Demo Import.

Plugin Slugolive-one-click-demo-import

Installations1,000+

VulnerabilityArbitrary File Upload

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched. You should deactivate the plugin.

Secure Admin IP

Product image for Secure Admin IP.

Plugin Slugsecure-admin-ip

Installations1,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Cartpauj Register Captcha

PluginCartpauj Register Captcha

Plugin Slugcartpauj-register-captcha

VulnerabilityBypass Vulnerability

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DX-auto-save-images

PluginDX-auto-save-images

Plugin Slugdx-auto-save-images

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FTP Access

PluginFTP Access

Plugin Slugftp-access

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

GuruWalk Affiliates

Plugin Slugguruwalk-affiliates

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Lock User Account

PluginLock User Account

Plugin Sluglock-user-account

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Maintenance Switch

PluginMaintenance Switch

Plugin Slugmaintenance-switch

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sticky Social Media Icons

PluginSticky Social Media Icons

Plugin Slugsticky-social-media-icons

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-08-30 12:48:28.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report – August 2, 2023

WordPress Vulnerability Report: October 2021, Part 1

Written by

Dan Knauss
on

August 2, 2023

Last Updated on August 2, 2023

Since last week, 94 total vulnerabilities emerged in public disclosure. They may affect over 7 million WordPress sites. There are 56 plugin vulnerabilities with security patches, so run those updates!

Additionally, there are 35 plugin vulnerabilities and three theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

FREE ONLINE TRAINING EVENT AUG 8TH @ 1:00 P.M. (CT)

New research from Snicco, WeWatchYourWebsite, Automattic-backed GridPane, and PatchStack claims WordPress security plugins with malware scanners are fundamentally flawed. And they’re being actively defeated by malware in the wild right now!

In this webinar, StellarWP technical writer Dan Knauss will explain the problem with malware scanners and the WordPress security best practices you need to implement to truly keep your sites safe.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

WPCode

Product image for WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager.

Plugin Sluginsert-headers-and-footers

Installations2,000,000+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in Version2.0.13.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.0.13.1.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.

Plugin Slugninja-forms

Installations800,000+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in Version3.6.26

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.6.26.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.

Plugin Slugninja-forms

Installations800,000+

VulnerabilitySubscriber+ Broken Access Control

Patched in Version3.6.26

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.6.26.

Ninja Forms

Product image for Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress.

Plugin Slugninja-forms

Installations800,000+

VulnerabilityContributor+ Broken Access Control

Patched in Version3.6.26

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.6.26.

The Events Calendar

Product image for The Events Calendar.

Plugin Slugthe-events-calendar

Installations800,000+

VulnerabilityBroken Access Control

Patched in Version6.1.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 6.1.3.

Duplicate Post

Product image for Duplicate Post.

Plugin Slugcopy-delete-posts

Installations200,000+

VulnerabilityMissing Authorization on handle_installation function

Patched in Version1.4.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.4.0.

Duplicate Post

Product image for Duplicate Post.

Plugin Slugcopy-delete-posts

Installations200,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.4.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.4.0.

Social Media Share Buttons & Social Sharing Icons

Product image for Social Media Share Buttons & Social Sharing Icons.

Plugin Slugultimate-social-media-icons

Installations200,000+

VulnerabilityBroken Access Control

Patched in Version2.8.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.8.2.

Social Media Share Buttons & Social Sharing Icons

Product image for Social Media Share Buttons & Social Sharing Icons.

Plugin Slugultimate-social-media-icons

Installations200,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.8.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.8.2.

TI WooCommerce Wishlist

Product image for TI WooCommerce Wishlist.

Plugin Slugti-woocommerce-wishlist

Installations100,000+

VulnerabilitySQL Injection

Patched in Version2.7.4

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.7.4.

Clone

Product image for Clone.

Plugin Slugwp-clone-by-wp-academy

Installations100,000+

VulnerabilityBroken Access Control

Patched in Version2.3.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.3.8.

Clone

Product image for Clone.

Plugin Slugwp-clone-by-wp-academy

Installations100,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.3.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.3.8.

Change WP Admin

Product image for Change WP Admin Login.

Plugin Slugchange-wp-admin-login

Installations90,000+

VulnerabilityBypass Vulnerability

Patched in Version1.1.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.4.

Backup Migration

Product image for Backup Migration.

Plugin Slugbackup-backup

Installations80,000+

VulnerabilityBroken Access Control

Patched in Version1.2.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.8.

Backup Migration

Product image for Backup Migration.

Plugin Slugbackup-backup

Installations80,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.2.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.8.

Simple Author Box

Product image for Simple Author Box.

Plugin Slugsimple-author-box

Installations60,000+

VulnerabilityInsecure Direct Object References (IDOR)

Patched in Version2.52

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.52.

Custom Field Template

Product image for Custom Field Template.

Plugin Slugcustom-field-template

Installations50,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.6.0

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.6.0.

Enhanced Text Widget

Product image for Enhanced Text Widget.

Plugin Slugenhanced-text-widget

Installations50,000+

VulnerabilityBroken Access Control

Patched in Version1.5.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.5.8.

Enhanced Text Widget

Product image for Enhanced Text Widget.

Plugin Slugenhanced-text-widget

Installations50,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.5.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.5.8.

ACF Photo Gallery Field

Product image for ACF Photo Gallery Field.

Plugin Slugnavz-photo-gallery

Installations50,000+

VulnerabilityBroken Access Control

Patched in Version2.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.0.

Quiz And Survey Master

Product image for Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress.

Plugin Slugquiz-master-next

Installations40,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version8.1.11

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 8.1.11.

Redirect Redirection

Product image for Redirection.

Plugin Slugredirect-redirection

Installations30,000+

VulnerabilityBroken Access Control

Patched in Version1.1.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.4.

Redirect Redirection

Product image for Redirection.

Plugin Slugredirect-redirection

Installations30,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.1.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.4.

Media from FTP

Product image for Media from FTP.

Plugin Slugmedia-from-ftp

Installations20,000+

VulnerabilityBroken Access Control

Patched in Version11.16

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 11.16.

PHP Everywhere

Product image for PHP Everywhere.

Plugin Slugphp-everywhere

Installations20,000+

VulnerabilityRemote Code Execution (RCE)

Patched in Version3.0.0

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.

Plugin Slugphp-everywhere

Installations20,000+

VulnerabilityRemote Code Execution (RCE)

Patched in Version3.0.0

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 3.0.0.

PHP Everywhere

Product image for PHP Everywhere.

Plugin Slugphp-everywhere

Installations20,000+

VulnerabilityRemote Code Execution (RCE)

Patched in Version3.0.0

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 3.0.0.

Video Conferencing with Zoom

Product image for Video Conferencing with Zoom.

Plugin Slugvideo-conferencing-with-zoom-api

Installations20,000+

VulnerabilitySensitive Data Exposure

Patched in Version4.2.2

Severity ScoreLow

The vulnerability has been patched, so you should update to version 4.2.2.

SSL Mixed Content Fix

Product image for SSL Mixed Content Fix.

Plugin Slughttp-https-remover

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version3.2.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.2.4.

SSL Mixed Content Fix

Product image for SSL Mixed Content Fix.

Plugin Slughttp-https-remover

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.2.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.2.4.

Pop-up

Product image for Pop-up.

Plugin Slugpop-up-pop-up

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version1.2.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.0.

Pop-up

Product image for Pop-up.

Plugin Slugpop-up-pop-up

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.2.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.0.

Ultimate Posts Widget

Product image for Ultimate Posts Widget.

Plugin Slugultimate-posts-widget

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version2.2.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.2.5.

Ultimate Posts Widget

Product image for Ultimate Posts Widget.

Plugin Slugultimate-posts-widget

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.2.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.2.5.

User Activity Log

Product image for User Activity Log.

Plugin Sluguser-activity-log

Installations10,000+

VulnerabilitySQL Injection

Patched in Version1.6.5

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 1.6.5.

Assistant

Product image for AI Content Writing Assistant (Content Writer, GPT 3 & 4, ChatGPT, Image Generator) All in One.

Plugin Slugai-content-writing-assistant

Installations4,000+

VulnerabilityServer Side Request Forgery (SSRF)

Patched in Version1.4.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.4.4.

Simple Blog Card

Plugin Slugsimple-blog-card

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.31

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.31.

Discussion Board

Product image for Discussion Board – WordPress Forum Plugin.

Plugin Slugwp-discussion-board

Installations3,000+

VulnerabilityContent Injection

Patched in Version2.4.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.4.9.

Contact Form Builder by Bit Form

Product image for Contact Form Builder by Bit Form – Easiest Contact Form, Payment Form, Order Form, Calculator Form Builder Plugin for WordPress.

Plugin Slugbit-form

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.2.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.2.0.

RSS Redirect & Feedburner Alternative

Product image for RSS Redirect & Feedburner Alternative.

Plugin Slugfeedburner-alternative-and-rss-redirect

Installations2,000+

VulnerabilityBroken Access Control

Patched in Version3.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.

RSS Redirect & Feedburner Alternative

Product image for RSS Redirect & Feedburner Alternative.

Plugin Slugfeedburner-alternative-and-rss-redirect

Installations2,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.

CodeBard’s Patron Button and Widgets for Patreon

Product image for CodeBard's Patron Button and Widgets for Patreon.

Plugin Slugpatron-button-and-widgets-by-codebard

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.1.9

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.1.9.

QR code MeCard/vCard generator

Product image for QR code MeCard/vCard generator.

Plugin Slugwp-qrcode-me-v-card

Installations2,000+

VulnerabilityBroken Access Control

Patched in Version1.6.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.1.

Church Admin

Product image for Church Admin.

Plugin Slugchurch-admin

Installations1,000+

VulnerabilityServer Side Request Forgery (SSRF)

Patched in Version3.8.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.0.

InstaWP Connect

Product image for InstaWP Connect – 1-click WP Staging & Migration (beta).

Plugin Sluginstawp-connect

Installations1,000+

VulnerabilityBroken Access Control

Patched in Version0.0.9.19

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 0.0.9.19.

Bit Assist

Product image for Chat Button: WhatsApp Chat, Facebook Messenger, Telegram Chat, WeChat, Line Chat, Discord Chat for Customer Support Chat with floating Chat Widget.

Plugin Slugbit-assist

Installations900+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.1.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.9.

WordPress Job Board and Recruitment Plugin – JobWP

Product image for WordPress Job Board and Recruitment Plugin – JobWP.

Plugin Slugjobwp

Installations300+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.0

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.0.

Local Development

Product image for Local Development.

Plugin Sluglocal-development

Installations100+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.8.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.8.3.

CartFlows Pro

PluginCartFlows Pro

Plugin Slugcartflows-pro

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.11.13

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.11.13.

Shop as a Customer for WooCommerce

PluginShop as a Customer for WooCommerce

Plugin Slugshop-as-a-customer-for-woocommerce

VulnerabilityPrivilege Escalation

Patched in Version1.2.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.2.4.

Shop as a Customer for WooCommerce

PluginShop as a Customer for WooCommerce

Plugin Slugshop-as-a-customer-for-woocommerce

VulnerabilityPrivilege Escalation

Patched in Version1.1.8

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.1.8.

Social Share Icons & Social Share Buttons

PluginSocial Share Icons & Social Share Buttons

Plugin Slugultimate-social-media-plus

VulnerabilityBroken Access Control

Patched in Version3.5.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.5.8.

Social Share Icons & Social Share Buttons

PluginSocial Share Icons & Social Share Buttons

Plugin Slugultimate-social-media-plus

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.5.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.5.8.

Schema Pro

PluginSchema Pro

Plugin Slugwp-schema-pro

VulnerabilityBroken Access Control

Patched in Version2.7.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.7.9.

WP Brutal AI

PluginWP Brutal AI

Plugin Slugwpbrutalai

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.06

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.06.

WPML String Translation

PluginWPML String Translation

Plugin Slugwpml-string-translation

VulnerabilitySQL Injection

Patched in Version3.2.6

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.2.6.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Optimize Database after Deleting Revisions

Product image for Optimize Database after Deleting Revisions.

Plugin Slugrvg-optimize-database

Installations100,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Booster for Woocommerce

Product image for Booster for WooCommerce.

Plugin Slugwoocommerce-jetpack

Installations60,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

WPS Limit Login

Product image for WPS Limit Login.

Plugin Slugwps-limit-login

Installations60,000+

VulnerabilityRace Condition

Patched in VersionNo Fix

Severity ScoreLow

The vulnerability has not been patched. You should deactivate the plugin.

Molongui

Product image for Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui.

Plugin Slugmolongui-authorship

Installations9,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Banner Management For WooCommerce

Product image for Banner Management For WooCommerce.

Plugin Slugbanner-management-for-woocommerce

Installations4,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Fraud Prevention For Woocommerce

Product image for Fraud Prevention For Woocommerce.

Plugin Slugwoo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers

Installations4,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

MultiParcels Shipping For WooCommerce

Product image for MultiParcels Shipping For WooCommerce.

Plugin Slugmultiparcels-shipping-for-woocommerce

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

WP Quick Post Duplicator

Product image for WP Quick Post Duplicator.

Plugin Slugwp-quick-post-duplicator

Installations3,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Mobile Address Bar Changer

Product image for Mobile Address Bar Changer.

Plugin Slugmobile-address-bar-changer

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Remove Duplicate Posts

Product image for Remove Duplicate Posts.

Plugin Slugremove-duplicate-posts

Installations1,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

APIExperts Square for WooCommerce

Product image for APIExperts Square for WooCommerce.

Plugin Slugwoosquare

Installations1,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Web Accessibility By accessiBe

PluginWeb Accessibility By accessiBe

Plugin Slugaccessibe

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Web Accessibility By accessiBe

PluginWeb Accessibility By accessiBe

Plugin Slugaccessibe

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

AGP Font Awesome Collection

PluginAGP Font Awesome Collection

Plugin Slugagp-font-awesome-collection

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Booster Elementor Addons

PluginBooster Elementor Addons

Plugin Slugbooster-for-elementor

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WP Clone Menu

PluginWP Clone Menu

Plugin Slugclone-menu

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Google Map Shortcode

PluginGoogle Map Shortcode

Plugin Sluggoogle-map-shortcode

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

HTTP Auth

PluginHTTP Auth

Plugin Slughttp-auth

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Instant CSS

PluginInstant CSS

Plugin Sluginstant-css

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

LWS Affiliation

PluginLWS Affiliation

Plugin Sluglws-affiliation

VulnerabilityLocal File Inclusion

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Meks Smart Social Widget

PluginMeks Smart Social Widget

Plugin Slugmeks-smart-social-widget

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Perelink Pro

PluginPerelink Pro

Plugin Slugperelink

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Quasar form

PluginQuasar form

Plugin Slugquasar-form

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Saphali Woocommerce Lite

PluginSaphali Woocommerce Lite

Plugin Slugsaphali-woocommerce-lite

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Googlebot Visit

PluginSimple Googlebot Visit

Plugin Slugsimple-googlebot-visit

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Wp Sitemap

PluginSimple Wp Sitemap

Plugin Slugsimple-wp-sitemap

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Slider Carousel – Responsive Image Slider

PluginSlider Carousel – Responsive Image Slider

Plugin Slugslider-images

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

PluginDonations Made Easy – Smart Donations

Plugin Slugsmart-donations

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Taboola

PluginTaboola

Plugin Slugtaboola

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

tagDiv Composer

PlugintagDiv Composer

Plugin Slugtd-composer

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Update Theme and Plugins from Zip File

PluginUpdate Theme and Plugins from Zip File

Plugin Slugupdate-theme-and-plugins-from-zip-file

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

User Email Verification for WooCommerce

PluginUser Email Verification for WooCommerce

Plugin Slugwoo-confirmation-email

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Database Administrator

PluginWP Database Administrator

Plugin Slugwp-database-admin

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wp tell a friend popup form

Pluginwp tell a friend popup form

Plugin Slugwp-tell-a-friend-popup-form

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

wp tell a friend popup form

Pluginwp tell a friend popup form

Plugin Slugwp-tell-a-friend-popup-form

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

nsc

Themensc

Theme Slugnsc

VulnerabilityPrototype Pollution to Reflected Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Winters

Themewinters

Theme Slugwinters

VulnerabilityPrototype Pollution to Reflected Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Your Journey

Themeyourjourney

Theme Slugyourjourney

VulnerabilityPrototype Pollution to Reflected Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-08-02 11:43:11.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report – August 23, 2023

WordPress Vulnerability Report

Written by

Dan Knauss
on

August 23, 2023

Last Updated on August 23, 2023

Since last week, 89 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 43 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!

Additionally, there are 37 plugin vulnerabilities and four theme vulnerabilities with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

“Lionel” was released on August 8, 2023. This release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

InfiniteWP Client

Plugin Slugiwp-client

Installations300,000+

VulnerabilitySensitive Data Exposure

Patched in Version1.12.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.12.1.

Advanced File Manager

Product image for Advanced File Manager.

Plugin Slugfile-manager-advanced

Installations100,000+

VulnerabilitySensitive Data Exposure

Patched in Version5.1.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.1.1.

Blog2Social

Product image for Blog2Social: Social Media Auto Post & Scheduler.

Plugin Slugblog2social

Installations70,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version7.2.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 7.2.1.

wpDataTables

Product image for wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin.

Plugin Slugwpdatatables

Installations70,000+

VulnerabilityPHP Object Injection

Patched in Version2.1.66

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.1.66.

WP-PostRatings

Product image for WP-PostRatings.

Plugin Slugwp-postratings

Installations50,000+

VulnerabilityBypass Vulnerability

Patched in Version1.91.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.91.1.

Cost Calculator Builder

Product image for Cost Calculator Builder.

Plugin Slugcost-calculator-builder

Installations30,000+

VulnerabilityBroken Access Control

Patched in Version3.1.43

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.1.43.

Countdown Timer Ultimate

Product image for Countdown Timer Ultimate.

Plugin Slugcountdown-timer-ultimate

Installations20,000+

VulnerabilityBroken Access Control

Patched in Version2.4.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.4.1.

Media from FTP

Product image for Media from FTP.

Plugin Slugmedia-from-ftp

Installations20,000+

VulnerabilitySettings Change

Patched in Version11.17

Severity ScoreLow

The vulnerability has been patched, so you should update to version 11.17.

User Submitted Posts

Product image for User Submitted Posts – Enable Users to Submit Posts from the Front End.

Plugin Sluguser-submitted-posts

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version20230811

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 20230811.

Album and Image Gallery plus Lightbox

Product image for Album and Image Gallery plus Lightbox.

Plugin Slugalbum-and-image-gallery-plus-lightbox

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version1.7.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.7.1.

Cookies and Content Security Policy

Product image for Cookies and Content Security Policy.

Plugin Slugcookies-and-content-security-policy

Installations10,000+

VulnerabilitySensitive Data Exposure

Patched in Version2.16

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.16.

Stripe Payment Plugin for WooCommerce

Product image for Stripe Payment Plugin for WooCommerce.

Plugin Slugpayment-gateway-stripe-and-woocommerce-integration

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version3.8.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.0.

Smart SEO Tool

Product image for Smart SEO Tool – SEO.

Plugin Slugsmart-seo-tool

Installations10,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version4.0.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.0.2.

Orders Tracking for WooCommerce

Product image for Orders Tracking for WooCommerce.

Plugin Slugwoo-orders-tracking

Installations10,000+

VulnerabilityDirectory Traversal

Patched in Version1.2.6

Severity ScoreLow

The vulnerability has been patched, so you should update to version 1.2.6.

Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget

Product image for Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget.

Plugin Slugwp-testimonial-with-widget

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version3.3.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.3.1.

WP VR

Product image for WP VR – 360 Panorama and Virtual Tour Builder For WordPress.

Plugin Slugwpvr

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version8.3.5

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 8.3.5.

Blog Designer – Post and Widget

Product image for Blog Designer – Post and Widget.

Plugin Slugblog-designer-for-post-and-widget

Installations8,000+

VulnerabilityBroken Access Control

Patched in Version2.5.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.5.2.

WP Remote Users Sync

Product image for WP Remote Users Sync.

Plugin Slugwp-remote-users-sync

Installations8,000+

VulnerabilityBroken Access Control

Patched in Version1.2.12

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.12.

WP Remote Users Sync

Product image for WP Remote Users Sync.

Plugin Slugwp-remote-users-sync

Installations8,000+

VulnerabilityServer Side Request Forgery (SSRF)

Patched in Version1.2.13

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.2.13.

Meta Slider and Carousel with Lightbox

Product image for Meta Slider and Carousel with Lightbox.

Plugin Slugmeta-slider-and-carousel-with-lightbox

Installations7,000+

VulnerabilityBroken Access Control

Patched in Version1.8.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.8.3.

Plausible Analytics

Product image for Plausible Analytics.

Plugin Slugplausible-analytics

Installations7,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.3.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.4.

Post grid and filter ultimate

Product image for Post grid and filter ultimate.

Plugin Slugpost-grid-and-filter-ultimate

Installations7,000+

VulnerabilityBroken Access Control

Patched in Version1.5.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.5.3.

Timeline and History slider

Product image for Timeline and History slider.

Plugin Slugtimeline-and-history-slider

Installations6,000+

VulnerabilityBroken Access Control

Patched in Version2.1.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.1.1.

JS Help Desk – Best Help Desk & Support Plugin

Product image for JS Help Desk – Best Help Desk & Support Plugin.

Plugin Slugjs-support-ticket

Installations5,000+

VulnerabilityArbitrary File Upload

Patched in Version2.7.8

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.7.8.

Team Slider and Team Grid Showcase plus Team Carousel

Product image for Team Slider and Team Grid Showcase plus Team Carousel.

Plugin Slugwp-team-showcase-and-slider

Installations4,000+

VulnerabilityBroken Access Control

Patched in Version2.6.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.6.1.

Trending/Popular Post Slider and Widget

Product image for Trending/Popular Post Slider and Widget.

Plugin Slugwp-trending-post-slider-and-widget

Installations4,000+

VulnerabilityBroken Access Control

Patched in Version1.6.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.1.

Video Gallery & Management

Product image for Video Gallery for YouTube Videos and WordPress.

Plugin Slugyoutube-showcase

Installations4,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.3.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.3.6.

Accordion and Accordion Slider

Product image for Accordion and Accordion Slider.

Plugin Slugaccordion-and-accordion-slider

Installations3,000+

VulnerabilityBroken Access Control

Patched in Version1.2.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.5.

DoLogin Security

Plugin Slugdologin

Installations3,000+

VulnerabilityBypass Vulnerability

Patched in Version3.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.7.

Video gallery and Player

Product image for Video gallery and Player.

Plugin Slughtml5-videogallery-plus-player

Installations3,000+

VulnerabilityBroken Access Control

Patched in Version2.6.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.6.6.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slugwoo-pdf-invoice-builder

Installations3,000+

VulnerabilityBroken Access Control

Patched in Version1.2.92

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.92.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slugwoo-pdf-invoice-builder

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.2.91

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.91.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slugwoo-pdf-invoice-builder

Installations3,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.2.91

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.91.

Accordion Slider

Product image for Accordion Slider.

Plugin Slugaccordion-slider

Installations2,000+

VulnerabilityBroken Access Control

Patched in Version1.9.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.9.7.

Doofinder for WooCommerce

Plugin Slugdoofinder-for-woocommerce

Installations2,000+

VulnerabilityOpen Redirection

Patched in Version2.0.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.0.0.

Portfolio and Projects

Product image for Portfolio and Projects.

Plugin Slugportfolio-and-projects

Installations2,000+

VulnerabilityBroken Access Control

Patched in Version1.3.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.8.

Post Ticker Ultimate

Product image for Post Ticker Ultimate.

Plugin Slugticker-ultimate

Installations2,000+

VulnerabilityBroken Access Control

Patched in Version1.5.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.5.6.

CLUEVO LMS

Product image for CLUEVO LMS, E-Learning Platform.

Plugin Slugcluevo-lms

Installations700+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.11.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.11.0.

Serial Codes Generator and Validator with WooCommerce Support

Product image for Serial Codes Generator and Validator with WooCommerce Support.

Plugin Slugserial-codes-generator-and-validator

Installations600+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.4.15

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.4.15.

Event Tickets with Ticket Scanner

Product image for Event Tickets with Ticket Scanner.

Plugin Slugevent-tickets-with-ticket-scanner

Installations500+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.5.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.5.5.

Products Quick View for WooCommerce

Product image for Products Quick View for WooCommerce.

Plugin Slugwoocommerce-products-quick-view

Installations100+

VulnerabilityBroken Access Control

Patched in Version2.3.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.3.0.

123.chat

Product image for 123.chat – 1:1 Live Video Chat Tool Plugin.

Plugin Slug123-chat-videochat

Installations40+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.3.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.1.

Paid Memberships Pro CCBill Gateway

PluginPaid Memberships Pro CCBill Gateway

Plugin Slugpmpro-ccbill

VulnerabilityBroken Access Control

Patched in Version0.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 0.4.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.

Plugin Slugsimple-urls

Installations5,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.

Plugin Slugsimple-urls

Installations5,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Simple URLs

Product image for Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management.

Plugin Slugsimple-urls

Installations5,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Enhanced Ecommerce Google Analytics for WooCommerce

Product image for Enhanced Ecommerce Google Analytics for WooCommerce.

Plugin Slugwoo-ecommerce-tracking-for-google-and-facebook

Installations3,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

GD Security Headers

Product image for GD Security Headers.

Plugin Sluggd-security-headers

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

LINE Notify

Plugin Slugwp-line-notify

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

fitness calculators plugin

Product image for fitness calculators plugin.

Plugin Slugfitness-calculators

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Kanban Boards for WordPress

Product image for Kanban Boards for WordPress.

Plugin Slugkanban

Installations1,000+

VulnerabilityArbitrary Code Execution

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched. You should deactivate the plugin.

Save as PDF plugin by Pdfcrowd

Plugin Slugsave-as-pdf-by-pdfcrowd

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Schedule Posts Calendar

Product image for Schedule Posts Calendar.

Plugin Slugschedule-posts-calendar

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Schedule Posts Calendar

Product image for Schedule Posts Calendar.

Plugin Slugschedule-posts-calendar

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Tabs & Accordion

Product image for Tabs & Accordion.

Plugin Slugtabs

Installations1,000+

VulnerabilityContent Injection

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Dynamic Pricing and Discount Rules for WooCommerce

Product image for Dynamic Pricing and Discount Rules for WooCommerce.

Plugin Slugwoo-conditional-discount-rules-for-checkout

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

rsvpmaker

Product image for RSVPMaker.

Plugin Slugrsvpmaker

Installations400+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

rsvpmaker

Product image for RSVPMaker.

Plugin Slugrsvpmaker

Installations400+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Save as Image plugin by Pdfcrowd

Plugin Slugsave-as-image-by-pdfcrowd

Installations50+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Typing Effect

PluginTyping Effect

Plugin Sluganimated-typing-effect

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Password Reset with Code for WordPress REST API

PluginPassword Reset with Code for WordPress REST API

Plugin Slugbdvs-password-reset

VulnerabilityBroken Authentication

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

BigBlueButton

PluginBigBlueButton

Plugin Slugbigbluebutton

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Carrot

PluginCarrot

Plugin Slugcarrrot

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cartpauj Register Captcha

PluginCartpauj Register Captcha

Plugin Slugcartpauj-register-captcha

VulnerabilityBypass Vulnerability

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Contact form 7 Custom validation

PluginContact form 7 Custom validation

Plugin Slugcf7-field-validation

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cleverwise Daily Quotes

PluginCleverwise Daily Quotes

Plugin Slugcleverwise-daily-quotes

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Cookies by JM

PluginCookies by JM

Plugin Slugcookies-by-jm

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

CT Commerce

PluginCT Commerce

Plugin Slugct-commerce

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Custom Admin Login Page | WPZest

PluginCustom Admin Login Page | WPZest

Plugin Slugcustom-admin-login-styler-wpzest

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

DX-auto-save-images

PluginDX-auto-save-images

Plugin Slugdx-auto-save-images

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Mortgage Calculator Estatik

PluginMortgage Calculator Estatik

Plugin Slugestatik-mortgage-calculator

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Make Paths Relative

PluginMake Paths Relative

Plugin Slugmake-paths-relative

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Org Chart

PluginSimple Org Chart

Plugin Slugsimple-org-chart

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Org Chart

PluginSimple Org Chart

Plugin Slugsimple-org-chart

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Simple Staff List

PluginSimple Staff List

Plugin Slugsimple-staff-list

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

PluginDonations Made Easy – Smart Donations

Plugin Slugsmart-donations

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Sticky Social Media Icons

PluginSticky Social Media Icons

Plugin Slugsticky-social-media-icons

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WebLibrarian

PluginWebLibrarian

Plugin Slugweblibrarian

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Putler Connector for WooCommerce

PluginPutler Connector for WooCommerce

Plugin Slugwoocommerce-putler-connector

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Putler Connector for WooCommerce

PluginPutler Connector for WooCommerce

Plugin Slugwoocommerce-putler-connector

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Bazaar Lite

Product image for Bazaar Lite.

Theme Slugbazaar-lite

Downloads70,170

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.8.6

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.8.6.

Aapna

Product image for Aapna.

Theme Slugaapna

Downloads34,228

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

College

Product image for College.

Theme Slugcollege

Downloads26,976

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.5.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.5.1.

BunnyPressLite

Product image for BunnyPressLite.

Theme Slugbunnypresslite

Downloads17,962

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.1.

Anfaust

Product image for Anfaust.

Theme Sluganfaust

Downloads17,345

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Brain Power

Product image for Brain Power.

Theme Slugbrain-power

Downloads15,015

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Cafe Bistro

Product image for Cafe Bistro.

Theme Slugcafe-bistro

Downloads10,047

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.1.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.1.4.

Anand

Product image for Anand.

Theme Sluganand

Downloads8,755

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Arendelle

Product image for Arendelle.

Theme Slugarendelle

Downloads8,504

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.1.3

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.1.3.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-08-23 14:31:22.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report – August 16, 2023

wordpress vulnerability report

Written by

Dan Knauss
on

August 16, 2023

Last Updated on August 16, 2023

Since last week, 90 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 49 plugin vulnerabilities and five theme vulnerabilities with security patches, so run those updates!

Additionally, there are 35 plugin vulnerabilities and one theme vulnerability with no patch available yet. If you use an unpatched plugin or theme, check their vendors’ intentions and progress on a security release. Suppose no patch is forthcoming or the vulnerable software has been marked “closed” and dropped from the official WordPress theme and plugin repositories. In that case, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core News

WordPress 6.3 “Lionel” is out! This new release of WordPress was built to help you “create beautiful and compelling websites more efficiently than ever.” See what’s new in WordPress 6.3.

Don’t forget to fully back up your website before installing WordPress 6.3. BackupBuddy, the industry-leading data protection and recovery solution for WordPress, will help you build a strong backup strategy to manage all updates. Embrace the enhanced content creation experience of WordPress 6.3 with confidence — and a backup copy of your website safely stored on a remote server.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins not updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new vulnerabilities that have emerged in plugins, themes, and/or WordPress core since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you find vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, representing the largest target for attackers.

Header Footer Code Manager

Plugin Slugheader-footer-code-manager

Installations400,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.1.35

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.1.35.

Gutenberg Blocks by Kadence Blocks – Page Builder

Product image for Gutenberg Blocks by Kadence Blocks – Page Builder Features.

Plugin Slugkadence-blocks

Installations300,000+

VulnerabilityArbitrary File Upload

Patched in Version3.1.11

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 3.1.11.

Ultimate Member

Product image for Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin.

Plugin Slugultimate-member

Installations200,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.6.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.6.9.

EmbedPress

Product image for EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor.

Plugin Slugembedpress

Installations80,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.8.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.3.

EmbedPress

Product image for EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor.

Plugin Slugembedpress

Installations80,000+

VulnerabilityBroken Access Control

Patched in Version3.8.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.3.

The Post Grid

Product image for The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid.

Plugin Slugthe-post-grid

Installations60,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version7.2.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 7.2.8.

Post Grid Combo

Product image for Post Grid Combo – 36+ Blocks for Gutenberg.

Plugin Slugpost-grid

Installations50,000+

VulnerabilitySensitive Data Exposure

Patched in Version2.2.51

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.2.51.

Profile Builder

Product image for Profile Builder – User Profile & User Registration Forms.

Plugin Slugprofile-builder

Installations50,000+

VulnerabilityBroken Access Control

Patched in Version3.9.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.9.8.

Chatbot

Product image for AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable.

Plugin Slugai-engine

Installations30,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version4.7.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.7.8.

Chatbot

Product image for AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable.

Plugin Slugai-engine

Installations30,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version4.7.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.7.8.

Popup by Supsystic

Product image for Popup by Supsystic.

Plugin Slugpopup-by-supsystic

Installations20,000+

VulnerabilityBroken Access Control

Patched in Version1.10.20

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.10.20.

Themesflat Addons For Elementor

Product image for Themesflat Addons For Elementor.

Plugin Slugthemesflat-addons-for-elementor

Installations20,000+

VulnerabilityPHP Object Injection

Patched in Version2.0.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.0.1.

Booking Package

Product image for Booking Package.

Plugin Slugbooking-package

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.6.02

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.6.02.

Justified Gallery

Product image for Justified Gallery.

Plugin Slugjustified-gallery

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version1.8.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.8.0.

Qubely

Product image for Qubely – Advanced Gutenberg Blocks.

Plugin Slugqubely

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version1.8.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.8.6.

User Activity Log

Product image for User Activity Log.

Plugin Sluguser-activity-log

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version1.6.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.6.

WP Project Manager

Product image for WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts.

Plugin Slugwedevs-project-manager

Installations10,000+

VulnerabilityBroken Access Control

Patched in Version2.6.5

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.6.5.

Premium Packages

Product image for Premium Packages – Sell Digital Products Securely.

Plugin Slugwpdm-premium-packages

Installations5,000+

VulnerabilityPrivilege Escalation

Patched in Version5.7.5

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 5.7.5.

Stock Ticker

Product image for Stock Ticker.

Plugin Slugstock-ticker

Installations4,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.23.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.23.4.

Stock Ticker

Product image for Stock Ticker.

Plugin Slugstock-ticker

Installations4,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.23.3

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.23.3.

Accordion and Accordion Slider

Product image for Accordion and Accordion Slider.

Plugin Slugaccordion-and-accordion-slider

Installations3,000+

VulnerabilityBroken Access Control

Patched in Version1.2.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.5.

Online Booking & Scheduling Calendar for WordPress by vcita

Product image for Online Booking & Scheduling Calendar for WordPress by vcita.

Plugin Slugmeeting-scheduler-by-vcita

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version4.3.3

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.3.3.

Paid Memberships Pro

Product image for Premium Courses & eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS & TutorLMS.

Plugin Slugpmpro-courses

Installations3,000+

VulnerabilityBroken Access Control

Patched in Version1.2.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.4.

Paid Memberships Pro

Product image for Premium Courses & eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS & TutorLMS.

Plugin Slugpmpro-courses

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version1.2.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.5.

User Activity Tracking and Log

Product image for User Activity Tracking and Log.

Plugin Sluguser-activity-tracking-and-log

Installations3,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version4.0.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.0.9.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slugwoo-pdf-invoice-builder

Installations3,000+

VulnerabilitySQL Injection

Patched in Version1.2.90

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.2.90.

WooCommerce PDF Invoice Builder

Product image for WooCommerce PDF Invoice Builder, Create invoices, packing slips and more.

Plugin Slugwoo-pdf-invoice-builder

Installations3,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.2.91

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.91.

ImageRecycle pdf & image compression

Product image for ImageRecycle pdf & image compression.

Plugin Slugimagerecycle-pdf-image-compression

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.1.12

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.1.12.

ImageRecycle pdf & image compression

Product image for ImageRecycle pdf & image compression.

Plugin Slugimagerecycle-pdf-image-compression

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.1.11

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.1.11.

Leyka

Product image for Leyka.

Plugin Slugleyka

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.30.3

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.30.3.

Portfolio and Projects

Product image for Portfolio and Projects.

Plugin Slugportfolio-and-projects

Installations2,000+

VulnerabilityBroken Access Control

Patched in Version1.3.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.3.8.

WP Testimonials

Product image for WP Testimonials.

Plugin Slugtestimonial-widgets

Installations2,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.4.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.4.3.

Atarim

Product image for Visual Website Collaboration, Feedback & Project Management – Atarim.

Plugin Slugatarim-visual-collaboration

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.9.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.9.4.

Bubble Menu

Product image for Bubble Menu – circle floating menu.

Plugin Slugbubble-menu

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.0.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.0.5.

Photo Gallery by Ays – Responsive Image Gallery

Product image for Photo Gallery by Ays – Responsive Image Gallery.

Plugin Sluggallery-photo-gallery

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version5.2.7

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.2.7.

POEditor

Product image for POEditor.

Plugin Slugpoeditor

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version0.9.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 0.9.8.

Sign-up Sheets

Product image for Sign-up Sheets.

Plugin Slugsign-up-sheets

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.2.9

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.2.9.

Post Timeline

Product image for Post Timeline.

Plugin Slugpost-timeline

Installations800+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.2.6

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.2.6.

wpShopGermany – Protected Shops

Plugin Slugwpshopgermany-protectedshops

Installations40+

VulnerabilityCross Site Scripting (XSS)

Patched in Version2.1

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.1.

Advanced Custom Fields Pro premium

PluginAdvanced Custom Fields PRO

Plugin Slugadvanced-custom-fields-pro

VulnerabilityCross Site Scripting (XSS)

Patched in Version6.1.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 6.1.8.

ARMember Premium

PluginARMember Premium

Plugin Slugarmember

VulnerabilityBroken Access Control

Patched in Version5.9.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.9.3.

Biometric Login for WooCommerce

PluginBiometric Login for WooCommerce

Plugin Slugbiometric-login-for-woocommerce

VulnerabilityPrivilege Escalation

Patched in Version1.0.4

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 1.0.4.

Avada Builder

PluginFusion Builder

Plugin Slugfusion-builder

VulnerabilityCross Site Scripting (XSS)

Patched in Version3.11.2

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

PluginFusion Builder

Plugin Slugfusion-builder

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.11.2

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

PluginFusion Builder

Plugin Slugfusion-builder

VulnerabilityBroken Access Control

Patched in Version3.11.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.11.2.

Avada Builder

PluginFusion Builder

Plugin Slugfusion-builder

VulnerabilitySQL Injection

Patched in Version3.11.2

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.11.2.

Jupiter X Core

PluginJupiterX Core

Plugin Slugjupiterx-core

VulnerabilityBroken Access Control

Patched in Version3.3.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.3.5.

Jupiter X Core

PluginJupiterX Core

Plugin Slugjupiterx-core

VulnerabilityBroken Access Control

Patched in Version3.3.5

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 3.3.5.

WooCommerce One Page Checkout

PluginWooCommerce One Page Checkout

Plugin Slugwoocommerce-one-page-checkout

VulnerabilityLocal File Inclusion

Patched in Version2.4.0

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 2.4.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Printful Integration for WooCommerce

Product image for Printful Integration for WooCommerce.

Plugin Slugprintful-shipping-for-woocommerce

Installations60,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP 404 Auto Redirect to Similar Post

Product image for WP 404 Auto Redirect to Similar Post.

Plugin Slugwp-404-auto-redirect-to-similar-post

Installations50,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

MailChimp Forms by MailMunch

Product image for MailChimp Forms by MailMunch.

Plugin Slugmailchimp-forms-by-mailmunch

Installations30,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

flowpaper

Product image for flowpaper.

Plugin Slugflowpaper-lite-pdf-flipbook

Installations20,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Futurio Extra

Product image for Futurio Extra.

Plugin Slugfuturio-extra

Installations20,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Email Template Designer – WP HTML Mail

Product image for Email Template Designer – WP HTML Mail.

Plugin Slugwp-html-mail

Installations20,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

PixTypes

Plugin Slugpixtypes

Installations10,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Theme Demo Import

Product image for Theme Demo Import.

Plugin Slugtheme-demo-import

Installations10,000+

VulnerabilityArbitrary File Upload

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched. You should deactivate the plugin.

WP Categories Widget

Product image for WP Categories Widget.

Plugin Slugwp-categories-widget

Installations8,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Product Attachment for WooCommerce

Product image for Product Attachment for WooCommerce.

Plugin Slugwoo-product-attachment

Installations6,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

SendPress Newsletters

Product image for SendPress Newsletters.

Plugin Slugsendpress

Installations5,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

YITH WooCommerce Waitlist

Product image for YITH WooCommerce Waitlist.

Plugin Slugyith-woocommerce-waiting-list

Installations5,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

BigBlueButton

Product image for BigBlueButton.

Plugin Slugbigbluebutton

Installations4,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Easy Cookie Law

Product image for Easy Cookie Law.

Plugin Slugeasy-cookie-law

Installations4,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Make Paths Relative

Product image for Make Paths Relative.

Plugin Slugmake-paths-relative

Installations4,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP Like Button

Product image for WP Like Button.

Plugin Slugwp-like-button

Installations4,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

LINE Notify

Plugin Slugwp-line-notify

Installations2,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Password Reset with Code for WordPress REST API

Product image for Password Reset with Code for WordPress REST API.

Plugin Slugbdvs-password-reset

Installations1,000+

VulnerabilityBroken Authentication

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched. You should deactivate the plugin.

Highcompress Image Compressor

Product image for Highcompress Image Compressor.

Plugin Slughigh-compress

Installations1,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Kangu para WooCommerce

Product image for Kangu para WooCommerce.

Plugin Slugkangu

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

SB Child List

Plugin Slugsb-child-list

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WxSync

Plugin Slugwxsync

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

wSecure Lite

Plugin Slugwsecure

Installations900+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Easy!Appointments

Product image for Easy!Appointments.

Plugin Slugeasyappointments

Installations800+

VulnerabilityArbitrary File Deletion

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Avartan Slider Lite

Product image for Responsive WordPress Slider – Avartan Slider Lite.

Plugin Slugavartan-slider-lite

Installations600+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

WebLibrarian

Product image for WebLibrarian.

Plugin Slugweblibrarian

Installations500+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

demon image annotation

Product image for demon image annotation.

Plugin Slugdemon-image-annotation

Installations10+

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Absolute Privacy

PluginAbsolute Privacy

Plugin Slugabsolute-privacy

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

All Users Messenger

PluginAll Users Messenger

Plugin Slugall-users-messenger

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Canto

PluginCanto

Plugin Slugcanto

VulnerabilityRemote File Inclusion

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FULL Customer

PluginFULL Customer

Plugin Slugfull-customer

VulnerabilitySensitive Data Exposure

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

FULL Customer

PluginFULL Customer

Plugin Slugfull-customer

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Real Estate Manager

PluginReal Estate Manager

Plugin Slugreal-estate-manager

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Realia

PluginRealia

Plugin Slugrealia

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Donations Made Easy – Smart Donations

PluginDonations Made Easy – Smart Donations

Plugin Slugsmart-donations

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information we provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you must find an alternative theme. Deactivate and delete persistently unpatched themes and those marked “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, delete it.

Avada

ThemeAvada

Theme Slugavada

VulnerabilityBroken Access Control

Patched in Version7.11.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 7.11.2.

Avada

ThemeAvada

Theme Slugavada

VulnerabilityArbitrary File Upload

Patched in Version7.11.2

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 7.11.2.

Avada

ThemeAvada

Theme Slugavada

VulnerabilityServer Side Request Forgery (SSRF)

Patched in Version7.11.2

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 7.11.2.

Avada

ThemeAvada

Theme Slugavada

VulnerabilityArbitrary File Upload

Patched in Version7.11.2

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 7.11.2.

BeTheme

ThemeBetheme

Theme Slugbetheme

VulnerabilityBroken Access Control

Patched in Version27.1.2

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 27.1.2.

Business Pro

ThemeBusiness Pro

Theme Slugbusiness-pro

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should switch themes.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-08-16 11:57:02.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

WordPress Vulnerability Report – July 5, 2023

WordPress Vulnerability Report: November 2021, Part 3

Written by

Dan Knauss
on

July 5, 2023

Last Updated on July 5, 2023

This week, 70 total vulnerabilities emerged in public disclosure. They may affect over one million WordPress sites. There are 36 plugin vulnerabilities that have security patches available, so run those updates!

Additionally, there are 33 plugin vulnerabilities and one theme vulnerability with no patch available yet. If you are using any unpatched plugins or themes, check their vendors’ intentions and progress on a security release. If no patch is forthcoming or the vulnerable software has been closed and dropped from the official WordPress theme and plugin repositories, you should consider deactivation and removal in favor of alternative solutions.

WordPress Core Vulnerabilities — Patched

  • No new WordPress core vulnerabilities were disclosed this week.

WordPress core is very secure when it’s properly configured and maintained. Vulnerable plugins that have not been updated by site owners are the most common vector for attacks on WordPress websites. Our weekly WordPress Vulnerability Report, powered by Patchstack, covers new WordPress plugin, theme, and core vulnerabilities that have emerged since last week’s report. Our goal is to spread awareness of emerging security threats and help you decide what to do if you are using vulnerable software on your website. For a deeper analysis of recent trends in WordPress vulnerabilities and threat vectors, see our 2022 Annual Vulnerability Report.

These reports are published every Wednesday and include all active vulnerabilities tracked by Patchstack as of Monday since the previous report. This leaves a 48-hour window for the newest emerging vulnerabilities to be patched before full public disclosure. iThemes Security Pro users have access to vulnerability alerts emerging within this window.

Get the weekly WordPress Vulnerability Report delivered to your inbox each Wednesday.

WordPress Plugin Vulnerabilities — Patched

In this section, you’ll find the most recently disclosed WordPress plugin vulnerabilities that have been fixed with a new release from their authors and maintainers. Please apply the updates if you are affected!

These vulnerabilities have been disclosed and scored for their severity, thanks to our friends at Patchstack. Each plugin listing includes the type of vulnerability with its CVE number and CVSS severity rating with links to more technical details. You’ll also see the number of active sites using the plugin and the plugin version release that patches the vulnerability. We start with the most popular plugins, which represent the largest target for attackers.

Formidable Forms

Plugin Slugformidable

Installations300,000+

VulnerabilityAuth. Remote Code Execution (RCE)

Patched in Version6.3.1

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 6.3.1.

Chaty

Product image for Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty.

Plugin Slugchaty

Installations200,000+

VulnerabilityAuthenticated Stored Cross Site Scripting (XSS)

Patched in Version3.1.2

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.1.2.

Ultimate Member

Product image for Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin.

Plugin Slugultimate-member

Installations200,000+

VulnerabilityUnauthenticated Privilege Escalation

Patched in Version2.6.7

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 2.6.7.

EmbedPress

Product image for EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor.

Plugin Slugembedpress

Installations80,000+

VulnerabilitySensitive Data Exposure

Patched in Version3.8.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.0.

Login/Signup Popup

Product image for Login/Signup Popup ( Inline Form + Woocommerce ).

Plugin Slugeasy-login-woocommerce

Installations30,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.4

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.4.

Social Login and Register

Product image for WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn).

Plugin Slugminiorange-login-openid

Installations30,000+

VulnerabilityAuthentication Broken Authentication

Patched in Version7.6.5

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 7.6.5.

Subscribe2

Product image for Subscribe2 – Form, Email Subscribers & Newsletters.

Plugin Slugsubscribe2

Installations30,000+

VulnerabilityBroken Access Control

Patched in Version10.41

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 10.41.

Subscribe2

Product image for Subscribe2 – Form, Email Subscribers & Newsletters.

Plugin Slugsubscribe2

Installations30,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version10.41

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 10.41.

Contact Form & Lead Form Elementor Builder

Product image for Responsive Contact Form Builder & Lead Generation Plugin.

Plugin Sluglead-form-builder

Installations20,000+

VulnerabilityBroken Access Control

Patched in Version1.8.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.8.5.

Supsystic Popup

Product image for Popup by Supsystic.

Plugin Slugpopup-by-supsystic

Installations20,000+

VulnerabilityPrototype Pollution

Patched in Version1.10.19

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.10.19.

WPGraphQL

Product image for WPGraphQL.

Plugin Slugwp-graphql

Installations20,000+

VulnerabilityServer Side Request Forgery (SSRF)

Patched in Version1.14.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.14.6.

WP ERP

Product image for WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting.

Plugin Slugerp

Installations9,000+

VulnerabilityReflected Cross Site Scripting (XSS)

Patched in Version1.12.4

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.12.4.

Active Directory Integration / LDAP Integration

Product image for Active Directory Integration / LDAP Integration.

Plugin Slugldap-login-for-intranet-sites

Installations5,000+

VulnerabilityUnauthenticated LDAP Injection

Patched in Version4.1.6

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.1.6.

MStore API

Product image for MStore API.

Plugin Slugmstore-api

Installations5,000+

VulnerabilityUnauth. SQL Injection

Patched in Version4.0.2

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 4.0.2.

Poll Maker

Product image for Poll Maker – Best WordPress Poll Plugin.

Plugin Slugpoll-maker

Installations5,000+

VulnerabilityServer Side Request Forgery (SSRF)

Patched in Version4.6.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.6.3.

Th Product Compare

Product image for Product Compare for WooCommerce.

Plugin Slugth-product-compare

Installations5,000+

VulnerabilityBroken Access Control

Patched in Version1.2.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.2.6.

Waitlist WooCommerce ( Back in stock notifier )

Product image for Waitlist Woocommerce ( Back in stock notifier ).

Plugin Slugwaitlist-woocommerce

Installations5,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.5.3

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.5.3.

Short URL

Product image for Short URL.

Plugin Slugshorten-url

Installations2,000+

VulnerabilityAuthenticated Stored Cross Site Scripting (XSS)

Patched in Version1.6.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.5.

Short URL

Product image for Short URL.

Plugin Slugshorten-url

Installations2,000+

VulnerabilitySQL Injection

Patched in Version1.6.5

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 1.6.5.

WP Inventory Manager

Product image for WP Inventory Manager.

Plugin Slugwp-inventory-manager

Installations2,000+

VulnerabilityInventory Items Deletion via Cross Site Request Forgery (CSRF)

Patched in Version2.1.0.14

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.1.0.14.

Kanban Boards for WordPress

Product image for Kanban Boards for WordPress.

Plugin Slugkanban

Installations1,000+

VulnerabilityAuth. Stored Cross Site Scripting (XSS)

Patched in Version2.5.21

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.5.21.

Request a Quote

Product image for Request a Quote.

Plugin Slugrequest-a-quote

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version2.3.11

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.3.11.

LiquidPoll

Product image for LiquidPoll – Advanced Polls for Creators and Brands.

Plugin Slugwp-poll

Installations1,000+

VulnerabilityBroken Access Control

Patched in Version3.3.69

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.3.69.

Front User Submit / Front Editor

Product image for Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor.

Plugin Slugfront-editor

Installations200+

VulnerabilityAuth. Stored Cross Site Scripting (XSS)

Patched in Version3.8.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.5.

TrustProfile

Plugin Slugtrustprofile

Installations200+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.25

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.25.

Knowledge Center

Product image for Easy Accordion FAQ and Knowledge Base Software for WordPress.

Plugin Slugknowledge-center

Installations20+

VulnerabilityAuthenticated Cross Site Scripting (XSS)

Patched in Version2.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.8.

Catalyst Connect Zoho CRM Client Portal

Product image for Catalyst Connect Zoho CRM Client Portal.

Plugin Slugcatalyst-connect-client-portal

Installations10+

VulnerabilityAuth. Stored Cross Site Scripting (XSS)

Patched in Version2.1.0

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 2.1.0.

ARMember

PluginARMember

Plugin Slugarmember-membership

VulnerabilityStored Cross Site Scripting (XSS) on Common Messages Settings

Patched in Version4.0.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 4.0.5.

AutomateWoo

PluginAutomateWoo

Plugin Slugautomatewoo

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version5.7.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.7.6.

AutomateWoo

PluginAutomateWoo

Plugin Slugautomatewoo

VulnerabilityBroken Access Control

Patched in Version5.7.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 5.7.6.

Houzez CRM

PluginHouzez CRM

Plugin Slughouzez-crm

VulnerabilitySQL Injection

Patched in Version1.3.5

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 1.3.5.

Salon Booking System

PluginSalon booking system

Plugin Slugsalon-booking-system

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version8.4.8

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 8.4.8.

LearnDash LMS

PluginLearnDash LMS

Plugin Slugsfwd-lms

VulnerabilityAuthenticated IDOR to Account Takeover

Patched in Version4.6.0.1

Severity ScoreHigh

The vulnerability has been patched, so you should update to version 4.6.0.1.

WooCommerce Order Barcodes

PluginWooCommerce Order Barcodes

Plugin Slugwoocommerce-order-barcodes

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version1.6.5

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 1.6.5.

WooCommerce Ship to Multiple Addresses

PluginWooCommerce Ship to Multiple Addresses

Plugin Slugwoocommerce-shipping-multiple-addresses

VulnerabilityCross Site Request Forgery (CSRF)

Patched in Version3.8.6

Severity ScoreMedium

The vulnerability has been patched, so you should update to version 3.8.6.

WP Post Author

PluginWP Post Author

Plugin Slugwp-post-author

VulnerabilityPrivilege Escalation

Patched in Version3.3.0

Severity ScoreCritical

The vulnerability has been patched, so you should update to version 3.3.0.

WordPress Plugin Vulnerabilities — Unpatched

This section contains plugin vulnerabilities with no known fix. Until a patch is available, you are advised to deactivate the plugin, at minimum, immediately. If there is a high risk of active exploits or the plugin remains unpatched for weeks, you are advised to delete the plugin. You should also delete persistently unpatched plugins the WordPress.org repository has locked and marked “Closed” so they can no longer be downloaded and installed.

Side Cart Woocommerce

Product image for Side Cart Woocommerce (Ajax).

Plugin Slugside-cart-woocommerce

Installations60,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Enhanced Text Widget

Product image for Enhanced Text Widget.

Plugin Slugenhanced-text-widget

Installations50,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Duplicate Post Page Menu & Custom Post Type

Product image for Duplicate Post Page Menu & Custom Post Type.

Plugin Slugduplicate-post-page-menu-custom-post-type

Installations30,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Zippy

Product image for Zippy.

Plugin Slugzippy

Installations10,000+

VulnerabilityPHP Object Injection

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Form Builder

Product image for Form Builder | Create Responsive Contact Forms.

Plugin Slugcontact-form-add

Installations6,000+

VulnerabilityCSV Injection

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Enable SVG, WebP & ICO Upload

Product image for Enable SVG, WebP & ICO Upload  .

Plugin Slugenable-svg-webp-ico-upload

Installations6,000+

VulnerabilityAuth. Stored Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

SW Product Bundles

Product image for SW Product Bundles.

Plugin Slugsw-product-bundles

Installations6,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

ApplyOnline – Application Form Builder and Manager

Product image for ApplyOnline – Application Form Builder and Manager.

Plugin Slugapply-online

Installations5,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Email download link

Product image for Email download link.

Plugin Slugemail-download-link

Installations5,000+

VulnerabilitySensitive Data Exposure

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Post Hit Counter

Product image for Post Hit Counter.

Plugin Slugpost-hit-counter

Installations3,000+

VulnerabilityBroken Access Control

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Layer Slider

Product image for Layer Slider.

Plugin Slugslider-slideshow

Installations3,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce Google Sheet Connector

Product image for WooCommerce Google Sheet Connector.

Plugin Slugwc-gsheetconnector

Installations1,000+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WCP OpenWeather

Product image for WCP OpenWeather.

Plugin Slugwcp-openweather

Installations1,000+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

WP Abstracts

Product image for WP Abstracts.

Plugin Slugwp-abstracts-manuscripts-manager

Installations400+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

WP Abstracts

Product image for WP Abstracts.

Plugin Slugwp-abstracts-manuscripts-manager

Installations400+

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Post to CSV by BestWebSoft

Product image for Post to CSV by BestWebSoft.

Plugin Slugpost-to-csv

Installations300+

VulnerabilityCSV Injection

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Caldera Forms Google Sheets Connector

Product image for Caldera Forms Google Sheets Connector.

Plugin Sluggsheetconnector-caldera-forms

Installations200+

VulnerabilityAccess Code Update via Cross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Autochat

Product image for Autochat Automatic Conversation.

Plugin Slugauyautochat-for-wp

Installations70+

VulnerabilityUnauth. Stored Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

Quiz Expert

Product image for Quiz Expert – Easy Quiz Maker, Exam and Test Manager.

Plugin Slugquiz-expert

Installations50+

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

AN_GradeBook

PluginAN_GradeBook

Plugin Slugan-gradebook

VulnerabilityAuthenticated SQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Booked

PluginBooked

Plugin Slugbooked

VulnerabilityUnauth. Appointment Data Exposure

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Editorial Calendar

PluginEditorial Calendar

Plugin Slugeditorial-calendar

VulnerabilityAuth. Stored Cross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Editorial Calendar

PluginEditorial Calendar

Plugin Slugeditorial-calendar

VulnerabilityInsecure Direct Object References (IDOR)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

File Manager Advanced Shortcode

PluginFile Manager Advanced Shortcode

Plugin Slugfile-manager-advanced-shortcode

VulnerabilityUnauth. Remote Code Execution (RCE)

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched. You should deactivate the plugin.

Image Map Pro Lite

PluginImage Map Pro

Plugin Slugimage-map-pro-lite

VulnerabilityCross-Site Request Forgery to Stored Cross-Site Scripting

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Image Map Pro

PluginImage Map Pro

Plugin Slugimage-map-pro-lite

VulnerabilityMissing Authorization to Stored Cross-Site Scripting

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Noo Timetable

PluginNOO Timetable

Plugin Slugnoo-timetable

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

Noo Timetable

PluginNOO Timetable

Plugin Slugnoo-timetable

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should deactivate the plugin.

SP Project & Document Manager

PluginSP Project & Document Manager

Plugin Slugsp-client-document-manager

VulnerabilityAuth. Insecure Direct Object References (IDOR)

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

SP Project & Document Manager

PluginSP Project & Document Manager

Plugin Slugsp-client-document-manager

VulnerabilitySQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

SP Project & Document Manager

PluginSP Project & Document Manager

Plugin Slugsp-client-document-manager

VulnerabilityCross Site Scripting (XSS)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

Web3

PluginWeb3 – Crypto wallet Login & NFT token gating

Plugin Slugweb3-authentication

VulnerabilityAuthentication Bypass Vulnerability

Patched in VersionNo Fix

Severity ScoreCritical

The vulnerability has not been patched and the plugin is closed. You should uninstall and delete the plugin.

WPJobBoard

PluginWPJobBoard

Plugin Slugwpjobboard

VulnerabilityUnauth. Blind SQL Injection

Patched in VersionNo Fix

Severity ScoreHigh

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Theme Vulnerabilities

In this section, you’ll find the latest WordPress theme vulnerabilities to be disclosed. You’ll see the same information provided above for vulnerable plugins, and the same advice applies. If a security update exists, install it immediately. If a vulnerability remains unpatched in a theme you are actively using, you will need to find an alternative theme. Deactivate and delete persistently unpatched themes and those that have been “Closed” in the WordPress.org theme repository. If you have a vulnerable theme installed that you are not actively using, simply delete it.

The7 — Website and eCommerce Builder for WordPress

ThemeThe7

Theme Slugdt-the7

VulnerabilityCross Site Request Forgery (CSRF)

Patched in VersionNo Fix

Severity ScoreMedium

The vulnerability has not been patched. You should switch themes.

Dan Knauss

Dan Knauss is StellarWP’s Technical Content Generalist. He’s been a writer, teacher, and freelancer working in open source since the late 1990s and with WordPress since 2004.

Keep reading the article at WordPress News | iThemes Blog. The article was originally written by Dan Knauss on 2023-07-05 11:20:56.

The article was hand-picked and curated for you by the Editorial Team of WP Archives.

Disclosure: Some of the links in this post are "affiliate links." This means if you click on the link and purchase the product, We may receive an affiliate commission.

Leave a Comment

Your email address will not be published. Required fields are marked *

Show Your ❤️ Love! Like Us
Scroll to Top